Security at Trueonic

Security belongs inthe product architecture.

Trueonic separates tenants, scopes access, encrypts sensitive data and preserves an audit trail across platform operations. This page describes implemented controls, not an unearned certification claim.

Live evidence
Enforced

Current analysis

Security controls

Tenant84%
Keys62%
Audit91%
RiskTenantKeysAuditEvidence
Evidence attached

AES-256-GCM

sensitive field encryption

SHA-256

stored API secret hashes

HMAC

signed webhooks

Built for the full investigation

Useful to engineering. Clear to fraud operations.

The same evidence powers API decisions and investigator views, so policy changes stay connected to the behavior behind them.

01

Tenant-scoped authorization

Project access is verified against organization membership on protected dashboard routes.

02

Credential protection

Passwords use scrypt; API secrets are shown once and stored only as cryptographic hashes.

03

Data lifecycle controls

Authorized teams can export or delete account data and configure retention expectations.

04

Operational traceability

Request IDs, API logs and audit records help teams reconstruct privileged actions and failures.

The operating flow

Move from signal to action without losing the explanation.

1

Use scoped credentials

Keep public keys in browsers and secret keys exclusively on trusted backend services.

2

Limit workspace access

Assign appropriate organization and project roles, then review team membership regularly.

3

Monitor integrations

Rotate keys, verify webhook signatures and use request logs to investigate anomalies.

Start with one protected workflow

Need to complete a security review?

Contact our team with your architecture, data-flow and control questions. We will answer precisely and avoid checkbox theater.

Get started