Draft pending legal review
This document reflects how TrustShot is built and operated, and is being reviewed by counsel before general availability. Highlighted items are details still to be confirmed. Questions: contact@trustshot.in
1.Hosting and data residency
The application, database and document storage run in Indian cloud regions. The public website is served through a global content delivery network. Providers and locations are listed on the Sub-processors page.
2.Encryption
- All traffic uses TLS 1.2 or later, with HTTP Strict Transport Security on our domains.
- Databases, document storage and backups are encrypted at rest by the hosting provider using AES-256.
- One-time codes and approval tokens are stored only as one-way hashes and expire quickly.
3.Access control
- TrustShot staff access to production requires multi-factor authentication and is limited to those who need it.
- Platform administration requires a time-based one-time password on every sign-in.
- Each customer’s data is scoped to its own tenant in every query, and restricted documents are served only to visitors whose access has been verified.
- Access is reviewed when roles change and removed when people leave.
4.Application security
- Signups require a verified corporate email and mobile number; consumer email domains are refused.
- Verification, sign-in and access-request endpoints are rate limited and protected against automated abuse.
- Restricted documents are shown in a watermarked viewer bearing the visitor’s verified email, and every view is logged.
- Pages are served with a Content Security Policy and other protective headers; dependencies are checked for known vulnerabilities before each release.
5.Logging and monitoring
Administrative actions, sign-ins, access grants and document views are recorded in append-only logs that customers can review for their own Trust Center. System logs are retained in India for at least the 180 days required by CERT-In’s directions of 28 April 2022.
6.Backups and recovery
The database is backed up automatically, backups are encrypted and kept in India, and restoration is tested. The service is designed so that the website stays available even when the application is being maintained.
7.Incident response
We follow a documented incident response process. We report cyber security incidents to CERT-In within six hours of noticing them, as its directions require; notify affected customers of a personal data breach within 24 hours of becoming aware, as set out in the Data Processing Addendum; and inform the Data Protection Board of India and affected individuals where the DPDP Act requires.
8.Certifications and assurance
TrustShot does not yet hold an ISO/IEC 27001 certificate or SOC 2 report, and we will not claim one until it is issued by an accredited auditor. Until then, we answer security questionnaires directly and share our policies under NDA. Ask at contact@trustshot.in.
9.Reporting a vulnerability
If you believe you have found a security issue, please follow our Responsible Disclosure Policy.