Tenant-scoped authorization
Project access is verified against organization membership on protected dashboard routes.
Security at Trueonic
Trueonic separates tenants, scopes access, encrypts sensitive data and preserves an audit trail across platform operations. This page describes implemented controls, not an unearned certification claim.
Current analysis
Security controls
AES-256-GCM
sensitive field encryption
SHA-256
stored API secret hashes
HMAC
signed webhooks
Built for the full investigation
The same evidence powers API decisions and investigator views, so policy changes stay connected to the behavior behind them.
Project access is verified against organization membership on protected dashboard routes.
Passwords use scrypt; API secrets are shown once and stored only as cryptographic hashes.
Authorized teams can export or delete account data and configure retention expectations.
Request IDs, API logs and audit records help teams reconstruct privileged actions and failures.
The operating flow
Keep public keys in browsers and secret keys exclusively on trusted backend services.
Assign appropriate organization and project roles, then review team membership regularly.
Rotate keys, verify webhook signatures and use request logs to investigate anomalies.
Start with one protected workflow
Contact our team with your architecture, data-flow and control questions. We will answer precisely and avoid checkbox theater.