- Reviewed
- 5 September 2026
- Production region
- Google Cloud · us-east1
- Security contact
- hello@trusec.ai
1. Assessment boundaries
- trusec.ai assessments are based on customer-provided facts and documented assumptions; they do not require live or production system access.
- Customers must not provide passwords, API keys, authentication tokens, sensitive customer datasets, special-category information or production credentials.
- Assessment access is restricted to authenticated users belonging to the organisation that owns the assessment.
2. Hosting and data location
The production application, PostgreSQL database, object storage and assessment jobs are hosted on Google Cloud in the us-east1 region in the United States. Google Cloud provides the underlying physical and cloud-platform safeguards.
- Public application traffic uses HTTPS.
- Application connections to Cloud SQL require encryption.
- Customer-upload buckets use uniform bucket-level access.
- Database backups, point-in-time recovery and deletion protection are enabled.
- Sensitive runtime configuration is injected through Google Secret Manager.
Cross-border processing and provider information is described in our Privacy Notice. Contract-specific residency requirements must be agreed before an assessment begins.
3. Identity and tenant access
- WorkOS provides sign-in, session and organisation-membership functions.
- Protected intake and report routes verify both the signed-in user and the owning organisation. Failed ownership checks do not reveal whether another customer’s resource exists.
- Raw secure-intake tokens are not stored in the application database. Their SHA-256 hashes are stored; active links expire after 21 days, and reissuing a link revokes the previous one. The token-bearing URL is delivered by email and may remain in the recipient’s mailbox and trusec.ai’s Microsoft Sent Items under the applicable mailbox-retention settings.
- Report downloads require authentication, organisation ownership and a released report. Downloads use private, no-store caching controls.
4. Assessment material and uploads
- Uploads are limited by count, size and supported type. File type is checked from file content rather than trusting the filename or browser-supplied MIME type.
- Storage object paths do not use customer filenames. Uploaded source files are kept in private cloud storage and are subject to a 365-day automatic deletion rule.
- A customer may remove a file while its intake remains editable. Extracted facts or released-report records may be retained separately under the applicable agreement and privacy notice.
- When configured AI-assisted document extraction, assessment analysis or controlled report narration runs, the content needed for that function is sent to the configured Anthropic service. Customers should submit only material authorised for that processing.
5. Report governance
- A report cannot be released until an authenticated, allowlisted reviewer has approved it.
- Released report packages are bound to their source and output hashes to make unauthorised or accidental changes detectable.
- Report downloads verify release state and stored integrity information before returning an artefact.
- Transactional email telemetry excludes message bodies, recipients, secrets and secure-link tokens.
6. Service providers
trusec.ai uses specialist providers for cloud hosting, identity, AI processing, email and payments. Current provider categories and the information they receive are listed in the Privacy Notice. Applicable statutory duties and restrictions operate independently of a contract. Additional contract-specific controls apply only if agreed. Do not submit third-party personal information until any legally required data-processing and transfer terms are in place; enterprise customers should confirm those requirements during procurement.
7. Security events
Customers should promptly use the channel below if they suspect unauthorised account or secure-link use. Any duty to investigate or notify affected customers or regulators is governed by applicable law and the customer’s contract. This page does not promise a particular response or resolution time.
8. Report a vulnerability
To request permission for security testing, email hello@trusec.ai before testing, with “Security testing request” in the subject and the proposed assets, methods, dates, source IPs and contact details. Do not begin unless trusec.ai confirms the permitted scope in writing.
To report an issue already discovered, use the same address with “Security report” in the subject. Include the affected URL or component, impact and reproducible steps, but do not include customer data, credentials or an unencrypted exploit containing sensitive information.
When investigating, do not:
- access, alter, retain or disclose another person’s data;
- disrupt service, degrade availability or use denial-of-service testing;
- use social engineering, physical intrusion or credential attacks; or
- continue testing after discovering sensitive information.
We assess reports using the information provided but do not promise an acknowledgement or remediation time. This channel does not authorise unlawful activity or testing outside a scope confirmed in writing.
9. Assurance and procurement
trusec.ai does not currently claim SOC 2 or ISO 27001 certification, a published independent penetration-test attestation, or Australian data residency. Security questionnaires, data-processing requirements and contract-specific controls should be agreed before purchase. Send procurement or security enquiries to hello@trusec.ai.