Security and Trust

Last updated: 5 October 2026

This page describes how TrustDyne protects customer data and what we have and have not independently certified.

Controls in place

  • AWS KMS customer-managed keys encrypt the database tables and storage buckets that hold customer data at rest
  • TLS enforced on all API endpoints
  • Uploaded firmware and app binaries are deleted, including stored versions, once analysis finishes
  • Scans run in ephemeral, isolated container sandboxes with no state kept between scans
  • Scan targets are checked against an allowlist and re-resolved at scan time to block internal and metadata addresses (SSRF protection)
  • Active testing only runs against domains whose ownership has been verified and consent recorded
  • AWS CloudTrail audit logging with log file validation to detect tampering
  • Application audit log of consent, scan and report-access events
  • Amazon Cognito authentication with JWT authorisation on API routes; optional TOTP multi-factor authentication
  • Least-privilege IAM roles scoped to each service
  • Container images are scanned on push to the registry
  • Customer reports are kept for 12 months and then deleted automatically

Certifications

TrustDyne does not hold any of the certifications below. They are on our roadmap.

Cyber Essentials Roadmap

UK Government-backed baseline for five technical controls. Not yet certified.

Cyber Essentials Plus Roadmap

Independently verified version of Cyber Essentials. Not yet certified.

ISO/IEC 27001 Roadmap

International information security management standard. Not yet certified.

SOC 2 Type II Roadmap

AICPA Trust Services Criteria audit. Not yet certified.

Vulnerability disclosure

If you find a security issue in TrustDyne, please report it through our public disclosure page or email security@trustdyne.com. We aim to acknowledge reports within 5 business days and to give a remediation timeline within 30 days. We will not pursue legal action against researchers who act in good faith, stay within scope, do not access or keep other people's data, and give us reasonable time to fix the issue.

Incident response

If a breach affects your data, we will tell affected customers without undue delay and, where we can, within 72 hours of becoming aware of it, so that you can meet your own reporting duties under UK GDPR.

Our own testing

We run TrustDyne's own scanners against our own infrastructure as part of ongoing vulnerability management. Summaries are available to customers under NDA on request.

Related documents