Skip to content
Request a demoView the portfolio

Trust

Trust center

What is attested, what is in place today, and who carries which responsibility. Last updated: August 28, 2026

Attestation status

Trunnion AI, LLC does not currently hold a third-party attestation or certification for this website or the Trunnion product platform, and does not claim one anywhere on this property. SOC 2 Type II is the target attestation framework for the product platform; an audit window has not been scheduled, and this page will publish dates and scope when it is. Statements like "aligned with" or "engineered to" on this site describe design and mapping objectives, not independent validation. See security posture and boundaries for how to evaluate a specific deployment.

Controls in place today

These are the controls operating on this website and its lead-capture path right now, stated so a reviewer can verify them from the outside where possible.

  • Transport security: HTTPS everywhere with HSTS preload, strict content security policy without inline script execution, frame denial, and content-type protections.
  • Privacy by default: Optional analytics is off until you opt in, advertising technology is not configured, Global Privacy Control is honored automatically, and reject carries the same visual weight as accept.
  • Lead-path controls: The contact and privacy-request forms post to a separate API with an origin allowlist, JSON-only requests, size and field limits, and request throttling.
  • Data minimization: Contact records are retained up to 365 days and privacy-request records up to 36 months, with log and backup ceilings published in the privacy notice.
  • Engineering gates: Every change passes blocking pipeline checks before deploy: automated WCAG 2.2 AA accessibility tests, dependency vulnerability audits for the site and the Go API, static analysis, and secret scanning.
  • Vulnerability disclosure: A published reporting channel with security.txt, acknowledged receipt, and coordinated validation and remediation.

Shared responsibility model

This website is a static site on a managed platform with a small lead API behind it. Responsibility for its controls divides as follows; the Trunnion product platform is deployed per customer environment and carries its own shared-responsibility model in the applicable agreement.

PartyLayerCarries
Render, Inc.Hosting and infrastructurePhysical security, network, and platform controls for the static site, its CDN, the lead API service, and the managed PostgreSQL database.
Trunnion AI, LLCApplication and dataSite and API code, input validation, security headers and content security policy, consent implementation, data retention and deletion, subprocessor selection, and incident response for this property.
Google LLCEmail deliveryTransport of lead and privacy-request notifications from the lead API to our staffed inbox.
You (the visitor)Your deviceBrowser security, the privacy choices you select, and not submitting restricted or sensitive information through public forms.

Data handling

What we collect, why, for how long, and the commitment that website-form data and customer tenant data are not used to train or fine-tune models are published in the Privacy Notice. The providers in the delivery path are listed at Subprocessors and service providers, and contracted processing is governed by the Data Processing Addendum.

AI governance and risk ownership

The Chief Technology Officer is accountable for the product AI-risk process, supported by product, security, privacy, legal, and the business owner for the affected workflow. A new or materially changed agent capability is not represented as production-ready until its intended use, prohibited uses, data and provider boundary, human-review path, evaluation plan, failure and abuse cases, monitoring, incident route, and release evidence have named owners. Reviews occur before release and again after a material model, prompt, tool, data-source, authorization, or deployment change. This is a governance process statement, not proof that a particular product control passed.

Incident response status

Trunnion AI maintains an incident-response process for this website and routes product incidents through the applicable customer support and security channels. The Chief Technology Officer owns technical coordination and the Chief Legal Officer owns legal and notification assessment. Reports are triaged by severity; customers and affected parties are notified within the time required by contract and applicable law. No last-tabletop date is currently published, so buyers should treat exercise evidence as open until supplied through diligence.

Related resources

Security posture and reporting · Subprocessors · Data Processing Addendum · AI Acceptable Use Policy · AI Transparency Notice · Accessibility Statement · Privacy Notice

Necessary technology is always active because it provides security and remembers this choice.