Security your enterprise
can verify
Every Troopr Labs product runs on one security program: SOC 2 Type II, ISO 27001, GDPR, and 99.9% uptime over 7 years. Independently audited every year, verifiable before you buy.
SOC 2 Type II
ISO 27001
GDPR ready
99.9% uptime over 7 years
600+
Enterprise deployments
30+
Countries served
99.9%
Uptime over 7 years
24h
Day refundable pilot
Trusted by startups and established enterprises


Independently audited, every year
One information security management system covers everything we ship. Third parties verify it annually.
SOC 2 Type II
An independent firm conducts an annual SOC 2 Type II audit covering the Common Criteria plus the Confidentiality and Privacy trust services criteria, backed by quarterly internal audits. Report available under NDA.
ISO 27001
Certified information security management system, maintained through annual third-party audits, governing how we manage security across the company.
GDPR and global privacy laws
GDPR, UK GDPR, Swiss FDPA, and US state privacy laws including CCPA as amended by CPRA. We act as a Service Provider under CCPA and do not sell or share personal data.
International transfers
EU, UK, and Swiss transfers are governed by the European Commission Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum.
PCI
We do not process cardholder data directly. Payments run through a third-party processor, with an annual PCI SAQ (A-EP) and monthly external scans of public-facing connections.
DPA and sub-processors
A standard Data Processing Addendum with SCCs, CCPA service-provider terms, and 30-day advance notice before any new sub-processor. Current list at trooprlabs.com/sub-processors.
Your data, protected by default
Encryption, isolation, and minimization are the baseline, not options.
Encrypted end to end
TLS 1.2+ in transit. AES-256 at rest across databases, file stores, and backups. Keys generated and managed in AWS KMS and rotated annually.
Data residency, your choice
Hosted on AWS with data residency in US or EU regions per your configuration. Additional infrastructure, including Microsoft Azure, is available for specific deployment requirements.
Tenant isolation
Customer data is stored with a unique tenant token that prevents any customer from reaching another customer's data.
Minimized and redacted
Automatic PII redaction, content filtering, masking, and data minimization. Configurable retention for AI interaction logs, including the option to disable interaction logging entirely.
Deleted on your schedule
On termination, your data is available to export for 30 days, then deleted within 90 days unless law requires continued storage.
Never used for training
Customer data is never used to train, fine-tune, or improve any model. Contractually enforced with every AI provider we use. Full detail on our AI Safety and Governance page.
Deploy where your policies require
The same security program applies whether we host or you do.
Cloud SaaS
Multi-tenant on AWS with US or EU data residency, running under our full certification scope.
Customer VPC
Run inside your own cloud account, available depending on product and plan.
On-premise
Deploy in your own infrastructure where regulation or policy demands it, available depending on product and plan.
Access under your control
Enterprise identity
SSO with SAML and OIDC, SCIM provisioning, and role-based access control aligned to least privilege. People see only what they need.
Connected-system permissions respected
Our products operate within the permissions of the systems they connect to and never bypass them. Authentication uses OAuth and documented public APIs.
Restricted production access
Production access is limited to a small group under explicit signed permission, reviewed quarterly. Personnel pass background screening, sign confidentiality terms, and complete security training. Access is revoked immediately on exit.
Full audit logging
Audit logs of high-severity events with search, filter, and CSV export, available to customers for security and compliance review.
99.9% uptime over 7 years
99.9%
Uptime, measured continuously since 2019
24x7
Premium support with uptime SLAs and defined escalation
Daily
Encrypted off-site backups, tested restores, defined RTO and RPO
2x
Incident response rehearsals per year, annual BIA and BCP reviews
Hosted in data centers carrying ISO 27001, FedRAMP, PCI, and SOC certifications, designed for resilient multi-region operations. Any confirmed data breach is communicated to your administrator within 24 hours.
Tested by us, and by people trying to break in
Continuous scanning and patching
Regular vulnerability scanning with automated patching, critical and high severity prioritized.
Annual penetration testing
Independent third-party penetration tests every year. Findings of medium severity and above are remediated. Reports available under NDA.
Active bug bounty
We run a bug bounty program on Bugcrowd and partner with ethical hackers to find and fix issues, remediated by severity. Report a vulnerability to security@trooprlabs.com.
Security in development
OWASP Top 10 validation before deployment, peer-reviewed code, continuous integration testing, and specialized developer security training.
Vendor risk management
Any vendor that could access sensitive data must provide an external audit or complete a risk interview, refreshed annually, with a signed DPA required.
Incident response
Documented incident response rehearsed twice a year. Any confirmed data breach is communicated to your administrator within 24 hours of confirmation.
The details security teams ask about
We process Customer Data solely to provide the services you subscribed to. We apply data minimization throughout: derived and structured information where possible rather than raw content, configurable retention, and deletion within 90 days of termination.
Customer data is stored in multi-tenant datastores and assigned a unique tenant token, which prevents one customer from accessing another customer's data. Dedicated deployment options are available where isolation requirements go further.
Production access is limited to a small group and granted only through signed permission, with a documented quarterly review. Personnel with access pass background screening, agree to confidentiality terms, and complete security training. Access is removed immediately on termination.
Yes. SAML and OIDC single sign-on, SCIM provisioning, and role-based access control on the principle of least privilege.
Yes. Audit logs cover access and administrative actions, with search, filter, and CSV export for security and compliance review.
All communication uses TLS 1.2+. All stored data is encrypted at rest with AES-256, including relational databases, file stores, and backups. Keys are managed by AWS KMS and rotated annually.
AWS data centers, with data residency in US or EU regions per your configuration. The hosting environment maintains ISO 27001, FedRAMP, PCI, and SOC certifications. Additional infrastructure, including Microsoft Azure, is available for specific deployment requirements.
Yes. Customer VPC and on-premise deployment options are available depending on product and plan.
Only sub-processors that have demonstrated sufficient security capabilities, each under a signed DPA. The current list is published at trooprlabs.com/sub-processors, with 30-day advance notice before any addition.
Yes. Systems are scanned regularly and patched automatically, with critical and high-severity fixes prioritized.
Yes. Independent penetration tests run annually. Medium and higher severity findings are remediated, with reports available under NDA.
Daily backups, encrypted in transit and at rest, stored off-site with regular restore tests and defined Recovery Time and Recovery Point Objectives. BIA and BCP are reviewed annually.
Daily backups, encrypted in transit and at rest, stored off-site with regular restore tests and defined Recovery Time and Recovery Point Objectives. BIA and BCP are reviewed annually.
Yes, documented and rehearsed twice a year. Any confirmed data breach is communicated to your administrator within 24 hours of confirmation.
An independent firm conducts an annual SOC 2 Type II audit covering the Common Criteria plus Confidentiality and Privacy, alongside quarterly internal audits and annual ISO 27001 surveillance.
Yes, an active program on Bugcrowd. Report a vulnerability to security@trooprlabs.com.
Everything your review needs
Read the full Terms of Service, Privacy Policy, Data Processing Addendum, and sub-processor list. Our security package for procurement review includes the SOC 2 Type II report and ISO 27001 certificate under NDA, which satisfies audit rights under GDPR Article 28(3)(h), a security overview covering data flow, encryption, and access controls, and an incident response summary.
Security & AI governance,
trusted by top enterprises
- SOC 2 Type II + ISO 27001 compliant; GDPR compliant
- TLS 1.2+ in transit, AES-256 at rest, keys via AWS KMS
- AI Guardrails for inputs/outputs + full audit logs
- Regular scans + pen tests (NDA), tested backups + IR plan
- 99.9% uptime for 6 years, proven at enterprise scale
