Resources

Frequently Asked Questions

Answers to what actually gets asked before a first scan. If something you need isn't here, email hello@trustdyne.com.

What counts as an "asset" I can scan?

Firmware, mobile apps (APK/IPA), web applications, and source code (via SBOM extraction or SARIF import) each count as one asset type. The Free plan includes 5 scans a month across any combination of these.

How does pricing work?

Free is £0/month for light testing. Starter is £99/month (£990/year) for your first full security review. Growth is £299/month (£2,990/year) for continuous, multi-asset scanning. Enterprise is custom-priced for multi-cloud, multi-framework organizations. Full details are in the pricing section of this page.

What is a Security Evidence Pack?

A single PDF containing your SBOM, prioritized vulnerabilities, AI-generated remediation guidance, and a compliance pass/fail mapping against the frameworks relevant to your product, generated automatically from a scan instead of assembled by hand for each vendor security review.

Do you store or retain our code and binaries?

No. Under Zero-Retention Analysis, uploaded binaries and code are analyzed inside an isolated cloud environment and immediately, permanently purged once the automated audit completes.

What is the Continuous Assurance Ledger?

An immutable, timestamped record of when your compliance status against each framework actually changed, so a buyer or auditor sees exactly when you became compliant, and whether you've stayed that way, instead of a single point-in-time snapshot.

How does the VDP Triage Portal work?

TrustDyne hosts a public vulnerability disclosure page for your organization. Incoming reports pass through a 3-layer AI filter that rejects spam and low-quality "beg bounty" submissions automatically; valid reports are scored and pushed straight to your team's triage inbox.

Can we import findings from tools we already use?

Yes. SARIF output from GitHub Advanced Security, CodeQL, or Semgrep, and Snyk exports, can all be ingested directly. Imported findings are normalized, deduped, and mapped against the same 23 compliance frameworks as a native TrustDyne scan.

Does TrustDyne check AI-generated code specifically?

Yes. Hallucinated Package Detection checks every dependency in your SBOM against the real PyPI, npm, and crates.io registries to catch packages an AI coding assistant referenced that don't actually exist. AI-Native Compliance Mapping also maps findings to EU AI Act, ISO 42001, and NIST AI RMF alongside your other frameworks.

Can this run in our CI/CD pipeline?

Yes, via the CI/CD Security Gate. Drop in the GitHub Action or GitLab pipeline step and every build is scanned automatically, with a structured pass/fail verdict tied to the specific commit and branch, so a regression is blocked before it merges.

What compliance frameworks do you support?

23 frameworks across software, AI, cloud, mobile, industrial, medical, and financial services, from ISO 27001 and SOC 2 to the EU AI Act, UK PSTI Act, and HIPAA. See the Compliance Framework Reference for what each one covers and how TrustDyne maps to it.