Security and Trust
Last updated: 5 October 2026
This page describes how TrustDyne protects customer data and what we have and have not independently certified.
Controls in place
- AWS KMS customer-managed keys encrypt the database tables and storage buckets that hold customer data at rest
- TLS enforced on all API endpoints
- Uploaded firmware and app binaries are deleted, including stored versions, once analysis finishes
- Scans run in ephemeral, isolated container sandboxes with no state kept between scans
- Scan targets are checked against an allowlist and re-resolved at scan time to block internal and metadata addresses (SSRF protection)
- Active testing only runs against domains whose ownership has been verified and consent recorded
- AWS CloudTrail audit logging with log file validation to detect tampering
- Application audit log of consent, scan and report-access events
- Amazon Cognito authentication with JWT authorisation on API routes; optional TOTP multi-factor authentication
- Least-privilege IAM roles scoped to each service
- Container images are scanned on push to the registry
- Customer reports are kept for 12 months and then deleted automatically
Certifications
TrustDyne does not hold any of the certifications below. They are on our roadmap.
Cyber Essentials Roadmap
UK Government-backed baseline for five technical controls. Not yet certified.
Cyber Essentials Plus Roadmap
Independently verified version of Cyber Essentials. Not yet certified.
ISO/IEC 27001 Roadmap
International information security management standard. Not yet certified.
SOC 2 Type II Roadmap
AICPA Trust Services Criteria audit. Not yet certified.
Vulnerability disclosure
If you find a security issue in TrustDyne, please report it through our public disclosure page or email security@trustdyne.com. We aim to acknowledge reports within 5 business days and to give a remediation timeline within 30 days. We will not pursue legal action against researchers who act in good faith, stay within scope, do not access or keep other people's data, and give us reasonable time to fix the issue.
Incident response
If a breach affects your data, we will tell affected customers without undue delay and, where we can, within 72 hours of becoming aware of it, so that you can meet your own reporting duties under UK GDPR.
Our own testing
We run TrustDyne's own scanners against our own infrastructure as part of ongoing vulnerability management. Summaries are available to customers under NDA on request.
Related documents
Privacy Policy · Data Processing Addendum · Sub-processors · Acceptable Use Policy
Security contact: security@trustdyne.com. Legal contact: legal@trustdyne.com.
TrustDyne