Back to home

Security

Last updated: July 2026

Biometric evidence demands the highest care. This page summarizes the controls Trusty applies today.

Encryption

TLS 1.3 in transit and server-side encryption at rest for every biometric artifact we store.

Storage

Images live in non-public buckets, reachable only through authenticated, audited proxy endpoints.

Tenant isolation

PII is isolated per tenant and deleted on cascade. JWT sessions are short-lived and scoped to SUPER_USER or CLIENT_ADMIN roles per tenant.

Webhooks

Each client gets an independent HMAC-SHA256 signing secret, rotatable from the dashboard. Public tokens only work from allowlisted origins.

Compliance programs

Designed for GDPR-aligned data handling. ISO 27001 and SOC 2 programs are not yet published. Ask your sales contact for the current status.

Reporting

To report a security issue or request the current security documentation, email [email protected].

Contact sales
Trusty