Certifications
ISO 27001 — in progress
Stage-1 audit complete. Stage-2 scheduled. We publish the certificate the day it is issued.
Where we are today
Certifications
Stage-1 audit complete. Stage-2 scheduled. We publish the certificate the day it is issued.
Residency
Customer data lives in Mumbai by default. Sub-processors documented in the DPA — no surprises.
Encryption
AES-256 at rest, TLS 1.3 in transit, key rotation on a schedule customers can audit.
Authentication
SAML and OIDC SSO with Okta, Azure AD and Google. SCIM provisioning included on Enterprise.
Authorisation
OAuth2 client credentials with fine-grained scopes. Least-privilege by default.
Events
Outbound webhooks signed with a rotating key. Replay protection enforced.
Logging
Cryptographic receipts on every consent and access event. Exportable to the Data Protection Board.
Scanners
truScanner and truFinder run inside your VPC. Personal data never leaves your network.
Disclosure
A published vulnerability disclosure policy at security@truconsent.io. We acknowledge within 24 hours.
What we hand to procurement
Subscribe to our newsletter and stay updated on DPDPA compliance insights.
By subscribing, you agree to receive updates from TruConsent.Unsubscribe anytime.
Protected by reCAPTCHA