Encryption, access control, and tenant isolation — the technical detail.
A governance platform holds your most sensitive operational data: control gaps, open risks, incident history, supplier weaknesses. The security of the platform itself is therefore not a feature checklist — it is the premise the whole product stands on.
The implementation, in terms a security team can evaluate rather than a marketing team wrote:
| Area | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 enforced on every external endpoint (TLS 1.2 only where a client does not negotiate 1.3) |
| Encryption at rest | AES-256, keys held in an external key-management service, rotation on a documented schedule |
| Tenant isolation | Customer Content logically segregated by tenant identifier at the persistence layer |
| Access control | Role-based access control across the multi-tenant SaaS deployment |
| Logging | Service-event logs with customer-configurable retention in the tenant settings |
| AI processing | Private inference on TruSecure-operated infrastructure by default — no shared public AI service |
Where your data actually lives
A governance record is among the most sensitive data you hold, so the deployment questions get specific answers rather than a security page's reassurances. Customer Content is processed in the EEA with one sub-processor, also in the EEA — no transfer to the United States or Asia. AI features run as private inference on TruSecure-operated infrastructure by default, not on a shared public AI service.
And the sub-processor list is published, not supplied on request: who processes what, where, and under which agreement — the same list your procurement team would score in a vendor assessment, available before the first call.
Verify, don't trust
The full program is published, versioned and dated on the Trust Center: the Security Statement, the SaaS Data Handling document, the sub-processor list, and the Data Processing Addendum. These are the documents your security and legal teams will ask for in due diligence — they are public because they should be.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.