Skip to main content
PLATFORM · SECURITY & PRIVACY

Encryption, access control, and tenant isolation — the technical detail.

A governance platform holds your most sensitive operational data: control gaps, open risks, incident history, supplier weaknesses. The security of the platform itself is therefore not a feature checklist — it is the premise the whole product stands on.

The implementation, in terms a security team can evaluate rather than a marketing team wrote:

Security implementation · as documented in the Security Statement
AreaImplementation
Encryption in transitTLS 1.3 enforced on every external endpoint (TLS 1.2 only where a client does not negotiate 1.3)
Encryption at restAES-256, keys held in an external key-management service, rotation on a documented schedule
Tenant isolationCustomer Content logically segregated by tenant identifier at the persistence layer
Access controlRole-based access control across the multi-tenant SaaS deployment
LoggingService-event logs with customer-configurable retention in the tenant settings
AI processingPrivate inference on TruSecure-operated infrastructure by default — no shared public AI service

Where your data actually lives

A governance record is among the most sensitive data you hold, so the deployment questions get specific answers rather than a security page's reassurances. Customer Content is processed in the EEA with one sub-processor, also in the EEA — no transfer to the United States or Asia. AI features run as private inference on TruSecure-operated infrastructure by default, not on a shared public AI service.

And the sub-processor list is published, not supplied on request: who processes what, where, and under which agreement — the same list your procurement team would score in a vendor assessment, available before the first call.

Verify, don't trust

The full program is published, versioned and dated on the Trust Center: the Security Statement, the SaaS Data Handling document, the sub-processor list, and the Data Processing Addendum. These are the documents your security and legal teams will ask for in due diligence — they are public because they should be.

Visit the Trust Center

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.