Security your enterprise
can verify

Every Troopr Labs product runs on one security program: SOC 2 Type II, ISO 27001, GDPR, and 99.9% uptime over 7 years. Independently audited every year, verifiable before you buy.

SOC 2 Type II

ISO 27001

GDPR ready

99.9% uptime over 7 years

600+

Enterprise deployments

30+

Countries served

99.9%

Uptime over 7 years

24h

Day refundable pilot

Trusted by startups and established enterprises

Independently audited, every year

One information security management system covers everything we ship. Third parties verify it annually.

SOC 2 Type II

An independent firm conducts an annual SOC 2 Type II audit covering the Common Criteria plus the Confidentiality and Privacy trust services criteria, backed by quarterly internal audits. Report available under NDA.

ISO 27001

Certified information security management system, maintained through annual third-party audits, governing how we manage security across the company.

GDPR and global privacy laws

GDPR, UK GDPR, Swiss FDPA, and US state privacy laws including CCPA as amended by CPRA. We act as a Service Provider under CCPA and do not sell or share personal data.

International transfers

EU, UK, and Swiss transfers are governed by the European Commission Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum.

PCI

We do not process cardholder data directly. Payments run through a third-party processor, with an annual PCI SAQ (A-EP) and monthly external scans of public-facing connections.

DPA and sub-processors

A standard Data Processing Addendum with SCCs, CCPA service-provider terms, and 30-day advance notice before any new sub-processor. Current list at trooprlabs.com/sub-processors.

Your data, protected by default

Encryption, isolation, and minimization are the baseline, not options.

Encrypted end to end

TLS 1.2+ in transit. AES-256 at rest across databases, file stores, and backups. Keys generated and managed in AWS KMS and rotated annually.

Data residency, your choice

Hosted on AWS with data residency in US or EU regions per your configuration. Additional infrastructure, including Microsoft Azure, is available for specific deployment requirements.

Tenant isolation

Customer data is stored with a unique tenant token that prevents any customer from reaching another customer's data.

Minimized and redacted

Automatic PII redaction, content filtering, masking, and data minimization. Configurable retention for AI interaction logs, including the option to disable interaction logging entirely.

Deleted on your schedule

On termination, your data is available to export for 30 days, then deleted within 90 days unless law requires continued storage.

Never used for training

Customer data is never used to train, fine-tune, or improve any model. Contractually enforced with every AI provider we use. Full detail on our AI Safety and Governance page.

Deploy where your policies require

The same security program applies whether we host or you do.

Cloud SaaS

Multi-tenant on AWS with US or EU data residency, running under our full certification scope.

Customer VPC

Run inside your own cloud account, available depending on product and plan.

On-premise

Deploy in your own infrastructure where regulation or policy demands it, available depending on product and plan.

Access under your control

Enterprise identity

SSO with SAML and OIDC, SCIM provisioning, and role-based access control aligned to least privilege. People see only what they need.

Connected-system permissions respected

Our products operate within the permissions of the systems they connect to and never bypass them. Authentication uses OAuth and documented public APIs.

Restricted production access

Production access is limited to a small group under explicit signed permission, reviewed quarterly. Personnel pass background screening, sign confidentiality terms, and complete security training. Access is revoked immediately on exit.

Full audit logging

Audit logs of high-severity events with search, filter, and CSV export, available to customers for security and compliance review.

99.9% uptime over 7 years

99.9%

Uptime, measured continuously since 2019

24x7

Premium support with uptime SLAs and defined escalation

Daily

Encrypted off-site backups, tested restores, defined RTO and RPO

2x

Incident response rehearsals per year, annual BIA and BCP reviews

Hosted in data centers carrying ISO 27001, FedRAMP, PCI, and SOC certifications, designed for resilient multi-region operations. Any confirmed data breach is communicated to your administrator within 24 hours.

Tested by us, and by people trying to break in

Continuous scanning and patching

Regular vulnerability scanning with automated patching, critical and high severity prioritized.

Annual penetration testing

Independent third-party penetration tests every year. Findings of medium severity and above are remediated. Reports available under NDA.

Active bug bounty

We run a bug bounty program on Bugcrowd and partner with ethical hackers to find and fix issues, remediated by severity. Report a vulnerability to security@trooprlabs.com.

Security in development

OWASP Top 10 validation before deployment, peer-reviewed code, continuous integration testing, and specialized developer security training.

Vendor risk management

Any vendor that could access sensitive data must provide an external audit or complete a risk interview, refreshed annually, with a signed DPA required.

Incident response

Documented incident response rehearsed twice a year. Any confirmed data breach is communicated to your administrator within 24 hours of confirmation.

The details security teams ask about

Do you store customer data?

We process Customer Data solely to provide the services you subscribed to. We apply data minimization throughout: derived and structured information where possible rather than raw content, configurable retention, and deletion within 90 days of termination.

How do you ensure no other customer sees my data?

Customer data is stored in multi-tenant datastores and assigned a unique tenant token, which prevents one customer from accessing another customer's data. Dedicated deployment options are available where isolation requirements go further.

How do you ensure no unauthorized Troopr Labs employees see my data?

Production access is limited to a small group and granted only through signed permission, with a documented quarterly review. Personnel with access pass background screening, agree to confidentiality terms, and complete security training. Access is removed immediately on termination.

Do you support SSO?

Yes. SAML and OIDC single sign-on, SCIM provisioning, and role-based access control on the principle of least privilege.

Can administrators see an audit trail?

Yes. Audit logs cover access and administrative actions, with search, filter, and CSV export for security and compliance review.

Is customer data encrypted?

All communication uses TLS 1.2+. All stored data is encrypted at rest with AES-256, including relational databases, file stores, and backups. Keys are managed by AWS KMS and rotated annually.

Where are your servers hosted?

AWS data centers, with data residency in US or EU regions per your configuration. The hosting environment maintains ISO 27001, FedRAMP, PCI, and SOC certifications. Additional infrastructure, including Microsoft Azure, is available for specific deployment requirements.

Can we deploy in our own environment?

Yes. Customer VPC and on-premise deployment options are available depending on product and plan.

Do third parties have access to my data?

Only sub-processors that have demonstrated sufficient security capabilities, each under a signed DPA. The current list is published at trooprlabs.com/sub-processors, with 30-day advance notice before any addition.

Do you scan for vulnerabilities?

Yes. Systems are scanned regularly and patched automatically, with critical and high-severity fixes prioritized.

Is your application penetration tested?

Yes. Independent penetration tests run annually. Medium and higher severity findings are remediated, with reports available under NDA.

What is your backup and recovery posture?

Daily backups, encrypted in transit and at rest, stored off-site with regular restore tests and defined Recovery Time and Recovery Point Objectives. BIA and BCP are reviewed annually.

What is your backup and recovery posture?

Daily backups, encrypted in transit and at rest, stored off-site with regular restore tests and defined Recovery Time and Recovery Point Objectives. BIA and BCP are reviewed annually.

Do you have an incident response program?

Yes, documented and rehearsed twice a year. Any confirmed data breach is communicated to your administrator within 24 hours of confirmation.

How do I know your security program is working?

An independent firm conducts an annual SOC 2 Type II audit covering the Common Criteria plus Confidentiality and Privacy, alongside quarterly internal audits and annual ISO 27001 surveillance.

Do you have a bug bounty program?

Yes, an active program on Bugcrowd. Report a vulnerability to security@trooprlabs.com.

Everything your review needs

Read the full Terms of Service, Privacy Policy, Data Processing Addendum, and sub-processor list. Our security package for procurement review includes the SOC 2 Type II report and ISO 27001 certificate under NDA, which satisfies audit rights under GDPR Article 28(3)(h), a security overview covering data flow, encryption, and access controls, and an incident response summary.

Security & AI governance,
trusted by top enterprises

  • SOC 2 Type II + ISO 27001 compliant; GDPR compliant
  • TLS 1.2+ in transit, AES-256 at rest, keys via AWS KMS
  • AI Guardrails for inputs/outputs + full audit logs
  • Regular scans + pen tests (NDA), tested backups + IR plan
  • 99.9% uptime for 6 years, proven at enterprise scale