Trust center

Controls, evidence, and the gaps we do not hide

TrustRail separates repository-verifiable controls from deployment evidence and external assurance. “Not measured” and “not certified” are states, not zeros.

Assurance register

AreaStatusEvidence boundary
Security architecturePublishedThirty invariants, threat boundaries, and evidence links
OIDC + bound JITImplementedProduction requires an organization binding; JIT cannot grant owner
SCIM deprovisioningImplementedMembership suspension, browser-session revocation, and transactional audit
Audit evidenceImplementedHash-chained NDJSON export and an offline verifier
CSV/PDF reportingImplementedOne normalized snapshot with explicit NOT_MEASURED values
SOC 2 Type I / IINot certifiedRequires an independent auditor opinion
ISO/IEC 27001 / 42001RoadmapNo certification badge or claim
External penetration testNot yet evidencedInternal adversarial tests are not called independent

Review the evidence

Architecture and threats

Control plane, execution plane, egress boundary, containment, and forensic plane.

Read the architecture →

Security invariants

The properties the implementation and database are required to preserve.

Review all thirty →

Vulnerability and incident handling

Report suspected vulnerabilities through the private security contact in the deployment or support agreement; do not place unpatched details in a public issue. TrustRail ships a disclosure policy and a technical incident-response runbook, but no bounty or independent response-time certification is implied.

Customer incidents preserve evidence first, restrict authority automatically, and require human-reviewed recovery. The forensic plane recommends; it cannot execute containment.