Last updated: July 2026
Biometric evidence demands the highest care. This page summarizes the controls Trusty applies today.
TLS 1.3 in transit and server-side encryption at rest for every biometric artifact we store.
Images live in non-public buckets, reachable only through authenticated, audited proxy endpoints.
PII is isolated per tenant and deleted on cascade. JWT sessions are short-lived and scoped to SUPER_USER or CLIENT_ADMIN roles per tenant.
Each client gets an independent HMAC-SHA256 signing secret, rotatable from the dashboard. Public tokens only work from allowlisted origins.
Designed for GDPR-aligned data handling. ISO 27001 and SOC 2 programs are not yet published. Ask your sales contact for the current status.
To report a security issue or request the current security documentation, email [email protected].