Skip to main content
PLATFORM · SECURITY & PRIVACY

Encryption, access control, and tenant isolation — the technical detail.

A governance platform holds your most sensitive operational data: control gaps, open risks, incident history, supplier weaknesses. The security of the platform itself is therefore not a feature checklist — it is the premise the whole product stands on.

The implementation, in terms a security team can evaluate rather than a marketing team wrote:

Security implementation · as documented in the Security Statement
AreaImplementation
Encryption in transitTLS 1.3 enforced on every external endpoint (TLS 1.2 only where a client does not negotiate 1.3)
Encryption at restAES-256, keys held in an external key-management service, rotation on a documented schedule
Tenant isolationCustomer Content logically segregated by tenant identifier at the persistence layer
Access controlRole-based access control across the multi-tenant SaaS deployment
LoggingService-event logs with customer-configurable retention in the tenant settings
AI processingPrivate inference on TruSecure-operated infrastructure by default — no shared public AI service

Where your data actually lives

A governance record is among the most sensitive data you hold, so the deployment questions get specific answers rather than a security page's reassurances. Customer Content is processed in the EEA with one sub-processor, also in the EEA — no transfer to the United States or Asia. AI features run as private inference on TruSecure-operated infrastructure by default, not on a shared public AI service.

And the sub-processor list is published, not supplied on request: who processes what, where, and under which agreement — the same list your procurement team would score in a vendor assessment, available before the first call.

Verify, don't trust

The full program is published, versioned and dated on the Trust Center: the Security Statement, the SaaS Data Handling document, the sub-processor list, and the Data Processing Addendum. These are the documents your security and legal teams will ask for in due diligence — they are public because they should be.

Visit the Trust Center

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

Frequently Asked Questions

How is Customer Content protected?
With encryption in transit and at rest, role-based access control, and a defined tenant-isolation model for the multi-tenant SaaS deployment — detailed on the security and privacy page.
Where is Customer Content stored?
With a single EU sub-processor — OVH — in French and German datacenters. The full sub-processor list is published on the Sub-processor List page.
Does TruSecure hold security certifications?
No certifications are currently held, and the published security statement says so plainly. The pages describe the measures actually operated rather than citing attestations that do not exist.