Skip to content
Request a demoView the portfolio

Security

Security posture and reporting

This page separates controls verified for the public marketing site from configurable product and deployment claims.

Public website scope

The marketing website is a static site delivered over HTTPS. Its public forms send information to a separate API that enforces an origin allowlist, JSON-only requests, size and field limits, request throttling, and security response headers. Contact and privacy-request records are stored in managed PostgreSQL and are subject to the retention periods in our Privacy Notice.

Do not send restricted data

This website and its public forms are not an approved channel for classified information, Controlled Unclassified Information (CUI), export-controlled technical data, procurement-sensitive or source-selection information, security credentials, incident evidence, or customer tenant data. Obtain a written approved channel and handling instructions before sharing restricted information.

Product and deployment claims

Trunnion product materials describe designed or configurable capabilities such as policy-based access control, tool authorization, human approval gates, execution records, model routing, tenant isolation, on-premise hosting, disconnected environments, classification-aware workflows, and standards-alignment mappings. Whether a capability exists, is enabled, meets a specific control, or is appropriate for a given classification must be established for the exact release, tenant, architecture, environment, personnel, configuration, and contract through technical evidence and the customer's required assessment and authorization process.

No certification or authorization by website statement

Trunnion AI does not claim through this website to hold an Authority to Operate, FedRAMP authorization, CMMC certification, SOC 2 report, security clearance, export authorization, or other third-party certification unless a current scoped evidence package expressly states it. Alignment language means a design or mapping objective, not independent validation. An authorizing official determines accreditation for a particular government system and environment. Current attestation status, the controls in place today, and the shared-responsibility model for this website are published on the trust center; the providers in the delivery path are listed at subprocessors, and the standard Data Processing Addendum covers contracted processing.

Customer review

Before production or regulated use, customers should require a current architecture and data-flow diagram; tenant-isolation test; model and provider inventory; retention, deletion, backup, and legal-hold behavior; access and key-management configuration; vulnerability and dependency results; audit-log content and integrity test; incident and recovery procedures; subprocessor and contract terms; and any required assessment, authorization, or export analysis.

Security and AI incident response

The Chief Technology Officer coordinates technical response and the Chief Legal Officer coordinates legal and notification assessment. A suspected compromise, cross-tenant exposure, unauthorized tool action, approval-gate bypass, harmful or materially incorrect consequential output, or loss of required audit evidence is treated as a reportable internal security or AI incident. We triage by severity, contain affected workflows, preserve evidence, investigate, correct, and notify customers or other affected parties within the time required by contract and applicable law. No public last-tabletop date is asserted; request current exercise evidence through diligence.

Report a vulnerability

Email contact@viceroynm.com with the affected URL or asset, reproducible steps, impact, and a safe way to contact you. Do not access data that is not yours, disrupt service, use social engineering, or place sensitive data in the report. We will acknowledge receipt and coordinate validation and remediation as appropriate. See security.txt for the machine-readable contact.

Necessary technology is always active because it provides security and remembers this choice.