Trust, Privacy & Legal Center
Security
Security at TRUSTTICA
- Version
- 1.0
- Effective
- August 15, 2026
- Last updated
- August 15, 2026
Identity Security
- KYC (Know Your Customer) checks against submitted identification
- ID verification against supported document types
- Selfie/ID comparison to help confirm the person presenting a document is its holder
- Liveness checks intended to detect replay, photo, or spoofing attempts
- Identity Lock to help flag reuse or duplication of the same identity across accounts
Account Security
- Password controls at account creation and change
- One-time passcodes (OTP) for email and phone verification
- Authentication required at sign-in
- Authorization checks and role-based access for business/team accounts
- Session security controls
Application Security
- Secure development practices
- Dependency management and monitoring
- Application testing
- Vulnerability remediation processes — see our Vulnerability Disclosure page
Data Security
- Encryption in transit (TLS) for data sent to and from TRUSTTICA
- Encryption at rest for stored data and files, provided by the underlying Azure database and storage services
- Least-privilege access controls
- Audit logging
- Secrets management
Infrastructure Security
- Environment isolation between development, staging and production
- Monitoring of production systems
- Backups
- Incident response procedures
Evidence Integrity
Evidence Vault records are tamper-evident: each stored file is fingerprinted with a SHA-256 hash at the time it is written, and a custody chain is recorded alongside it. Any later change to the underlying file would no longer match its recorded hash.
Report a Vulnerability
If you believe you've found a security vulnerability, please see our Vulnerability Disclosure page for how to report it responsibly.
Questions about this document? Contact support@trusttica.com or call +1 (512) 884-0373.