Trust, stated plainly.
You are evaluating a platform that will hold your control environment. Here is ours, in the terms we would ask of any vendor — including what belongs on a webpage and what belongs in an NDA.
- You are running vendor due diligence on TruOps and need more than a SOC 2 logo
- InfoSec asked for subprocessors, AI data use, and how isolation actually works
- You will not accept an AI that can write to the register with no human gate
Independent assurance
TruOps holds a SOC 2 Type II report covering all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The report is available to customers and prospects under NDA. We do not publish a redacted PDF on this page; a security review is how you get the real package.
| Item | Detail |
|---|---|
| Report | SOC 2 Type II |
| Criteria | Security · Availability · Processing Integrity · Confidentiality · Privacy |
| Most recent period | 15 November 2024 to 15 May 2025 |
| Access | Under NDA: request a security review |
How a security review actually runs
A serious buyer does not want a marketing page. They want a packet and a walkthrough. Request a security review (or email hello@truops.ai) and we send, under NDA:
- The current SOC 2 Type II report.
- A current subprocessor list and a description of hosting. We do not post those lists here because they change; the NDA packet is the source of truth.
- A data-processing addendum discussion, including how customer content is used (it is not used to train foundation models).
- Architecture enough to evaluate tenant isolation, encryption in transit and at rest, access control, and logging — without a public diagram that becomes stale.
- Answers to your SIG, CAIQ, or custom security questionnaire, pre-filled from our own program where we can, cited, with gaps left for a person.
How the platform protects you
- Tenant isolation. Every environment, whether an enterprise, an MSSP client, or a portfolio company, has its own data, evidence, and access boundary. Data does not cross tenants. Context switches are explicit and logged.
- Fine-grained access. Role- and attribute-based permissions apply to people and AI agents alike. TruPilot acts with scoped rights, not as an unbounded admin.
- Read-only integrations. Connectors observe Azure, AWS, Google Cloud, Entra ID, Okta, Intune, Defender, CrowdStrike, Tenable, Qualys, GitHub, and Azure DevOps with least-privilege scopes, revocable at any time. They do not change your configuration.
- One audit log. Every action, human or agent, is recorded. Completed assessment results are saved as of their date.
- AI data use. Your documents, telemetry, and corrections improve your own tenant. They are not used to train foundation models or shared across tenants. See Commitments.
Bring one real document. Watch the program get set up from it.
What we will not claim from a webpage
Security pages fail when they invent a region, a pentest firm, or a certification they do not hold. If it is not below, ask us under NDA rather than assuming it.
| Question | Honest answer |
|---|---|
| Do you have ISO 27001 as TruOps the company? | Our customer-facing assurance today is SOC 2 Type II (all five criteria). Do not treat this page as an ISO certificate for TruOps. |
| Where is data hosted? | Walked through in the security review. Hosting and subprocessors belong in the NDA packet, not in copy that will be wrong next quarter. |
| Do you pentest? | Ask in the review. We will not name a firm or a date here that we then have to keep current in marketing HTML. |
| Can we have a DPA / BAA? | Discussed as part of contracting. Healthcare customers who need a BAA should say so in the security-review email. |
| Incident reporting | Email hello@truops.ai with “Security incident”. Contractual notification terms are in the agreement, not on this page. |
How to evaluate our AI as a control
If TruOps will draft assessments in your environment, treat the AI the way you would treat a privileged contractor.
- ProvenanceEvery drafted answer must show its source and confidence. If it cannot, it must stay blank.
- Separation of dutiesWhatever produced a value cannot approve it. Watch an assessment complete in a demo.
- LoggingAccept, reject, and override must land in the same audit log as human work.
- ScopeAgents and connectors must run with least privilege. Connectors are read-only.
- DecayStatus must drop when evidence goes stale. A permanently green control is a dashboard, not CCM.
The test is written up as Agents without a human gate.
Our AI commitments
How TruOps' AI behaves — citing sources, never approving its own work, confidence routing, least-privilege agents, asking when unsure, one audit log — is published on our Commitments page. That page is the product rulebook. This page is the security review.
Questions
Does TruOps have a SOC 2 report?
Yes. TruOps holds a SOC 2 Type II report covering Security, Availability, Processing Integrity, Confidentiality, and Privacy, for the period 15 November 2024 to 15 May 2025, available under NDA.
Is customer data used to train AI models?
No.
Can we see subprocessors and hosting?
Yes, under NDA, as part of a security review. We do not publish a live list on this page because it goes stale.
Are integrations read-only?
Yes. Connectors observe your systems; they do not change configuration. Proposed changes are drafts for a person.
Does TruOps replace our auditor?
No. Only a licensed auditor can issue a SOC 2 report. TruOps is the program and evidence layer you take into fieldwork.
How do I start a security review?
Use the contact form and pick “A security review”, or email hello@truops.ai. Send your NDA or use ours, plus any questionnaire you need us to complete.
Related
How TruOps AI behaves, and how you verify it in a demo.
→LearnAgents without a human gateWhy an ungoverned GRC agent is a liability, not a feature.
→PlatformIntegrationsSecurity stack plus 800+ TruOps integrations — cloud, identity, EDR, HRIS, ITSM, and the rest of your tools.
→PlatformMulti-tenantEvery client or entity isolated, with a parent-level view.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.