TrustDesk

Control & Evidence Library

16approved controls TrustDesk drafts answers from. Freshness is computed from each control's review and expiry dates — stale evidence is surfaced first because it gates automation.

11
Current
Current
3
Expiring Soon
Expiring Soon
2
Expired
Expired
PRIV-PII-041

Subprocessors & PII Handling

Privacy & Data Retention

Expired
GDPR

A current list of subprocessors is maintained and published. Subprocessors are bound by data protection agreements, and customers are notified of material changes with the opportunity to object.

Evidence owner
Helena Brooks
Privacy
Last reviewed
Apr 22, 2025
Expires
Apr 22, 2026
SEC-VM-031

Patch Management SLA

Vulnerability Management

Expired
SOC 2

Security patches are prioritized by severity. Critical vulnerabilities are remediated within defined SLA windows, tracked to closure, and reported to security leadership.

Evidence owner
Sofia Marchetti
Security Operations
Last reviewed
Mar 30, 2025
Expires
Mar 30, 2026
AI-GOV-060

AI & Model Governance

AI & Model Governance

Expiring Soon
NIST AI RMFISO 27001

AI features operate under a documented governance program covering approved use cases, data handling, human oversight, and evaluation. Customer data is not used to train shared or third-party foundation models without explicit consent.

Evidence owner
Helena Brooks
AI Governance
Last reviewed
Sep 30, 2025
Expires
Jul 30, 2026
SEC-IR-021

Breach Notification Commitments

Incident Response

Expiring Soon
GDPRSOC 2

Customers are notified of confirmed breaches affecting their data without undue delay and within the timelines defined in the applicable agreement and regulation. Regulatory notifications follow documented runbooks.

Evidence owner
Tomas Reyes
Security Operations
Last reviewed
Jun 20, 2025
Expires
Jun 20, 2026
SEC-KMS-004

Key Management & Rotation

Encryption & Data Protection

Expiring Soon
SOC 2ISO 27001

Encryption keys are managed in a dedicated KMS with hardware-backed protection. Keys are rotated at least annually and on personnel change, with access restricted by least privilege.

Evidence owner
Raj Patel
Platform Security
Last reviewed
Jul 15, 2025
Expires
Jul 15, 2026
BC-DR-070

Business Continuity & Disaster Recovery

Business Continuity & Resilience

Current
SOC 2ISO 27001

Business continuity and disaster recovery plans define RTO and RPO targets, are tested at least annually, and rely on geographically redundant infrastructure with automated, regularly validated backups.

Evidence owner
Tomas Reyes
Security Operations
Last reviewed
Mar 22, 2026
Expires
Mar 22, 2027
CLD-INF-050

Cloud Hosting & Tenant Segregation

Cloud & Infrastructure Security

Current
SOC 2ISO 27001

The platform is hosted on a major cloud provider in a logically segregated, multi-tenant architecture. Network controls, security groups, and private subnets isolate production workloads from other environments.

Evidence owner
Raj Patel
Platform Security
Last reviewed
Feb 14, 2026
Expires
Feb 14, 2027
CMP-CERT-090

Compliance Certifications

Compliance & Certifications

Current
SOC 2ISO 27001CSA CAIQ

The company maintains a SOC 2 Type II report and ISO/IEC 27001 certification. Reports and certificates are available to customers and prospects under NDA through the trust portal.

Evidence owner
Sofia Marchetti
Governance, Risk & Compliance
Last reviewed
May 1, 2026
Expires
May 1, 2027
PRIV-DR-040

Data Retention & Deletion

Privacy & Data Retention

Current
GDPRISO 27001

Customer data is retained only as long as necessary to provide the service or meet legal obligations. On contract termination, customer data is deleted or returned within the period defined in the data processing agreement.

Evidence owner
Helena Brooks
Privacy
Last reviewed
Jan 12, 2026
Expires
Jan 12, 2027
SEC-ENC-001

Encryption at Rest

Encryption & Data Protection

Current
SOC 2ISO 27001PCI DSS

All customer data is encrypted at rest using AES-256. Encryption is enabled at the storage layer across all production data stores, including backups and snapshots.

Evidence owner
Dana Whitfield
Security Engineering
Last reviewed
Feb 10, 2026
Expires
Feb 10, 2027
SEC-ENC-002

Encryption in Transit

Encryption & Data Protection

Current
SOC 2ISO 27001

All data in transit is protected using TLS 1.2 or higher. Legacy protocols (SSL, TLS 1.0/1.1) are disabled, and HSTS is enforced on all public endpoints.

Evidence owner
Dana Whitfield
Security Engineering
Last reviewed
Mar 1, 2026
Expires
Mar 1, 2027
SEC-IAM-010

Access Control & RBAC

Access Control & Identity

Current
SOC 2ISO 27001NIST CSF

Access to production systems follows role-based access control and least privilege. Access is provisioned through approved requests, reviewed quarterly, and revoked promptly on role change or offboarding.

Evidence owner
Mara Lindgren
Identity & Access
Last reviewed
Jan 20, 2026
Expires
Jan 20, 2027
SEC-IAM-011

MFA & Single Sign-On

Access Control & Identity

Current
SOC 2NIST CSF

Multi-factor authentication is enforced for all employee and administrative access. Workforce access is federated through SSO with phishing-resistant factors required for privileged roles.

Evidence owner
Mara Lindgren
Identity & Access
Last reviewed
Feb 28, 2026
Expires
Feb 28, 2027
SEC-IR-020

Incident Response Plan

Incident Response

Current
SOC 2ISO 27001NIST CSF

A documented incident response plan defines roles, severity tiers, and escalation paths. The plan is tested at least annually through tabletop exercises, and post-incident reviews are conducted for all major incidents.

Evidence owner
Tomas Reyes
Security Operations
Last reviewed
Apr 5, 2026
Expires
Apr 5, 2027
SEC-VM-030

Vulnerability Management & Penetration Testing

Vulnerability Management

Current
SOC 2ISO 27001

Continuous vulnerability scanning runs across production and build pipelines. Independent third-party penetration tests are performed at least annually, and an executive summary is available under NDA.

Evidence owner
Sofia Marchetti
Security Operations
Last reviewed
Mar 18, 2026
Expires
Mar 18, 2027
VR-TPR-080

Vendor & Third-Party Risk Management

Vendor & Third-Party Risk

Current
SOC 2ISO 27001

Vendors are risk-assessed before onboarding and reassessed periodically based on data sensitivity and criticality. Security and privacy requirements are flowed down through contractual terms.

Evidence owner
Mara Lindgren
Governance, Risk & Compliance
Last reviewed
Apr 10, 2026
Expires
Apr 10, 2027