SECURITY & TRUST
How TruthSource Protects Your Data
We follow a strict privacy-first architecture. Files are hashed client-side. We store proofs, not originals.
🔐
Encryption
At-rest encryptionAES-256 — all database records and stored metadata
In-transitTLS 1.3 — all API and dashboard connections
File handlingSHA-256 computed client-side. Original files never transmitted unless Vault is enabled.
Key managementAWS KMS (Frankfurt region)
🏗️
Infrastructure
Data processing regionEU-Frankfurt (AWS eu-central-1)
Blockchain networkPolygon Mainnet for production. Isolated Amoy Testnet available exclusively for API sandbox environments (tsk_test_ keys).
DatabaseIsolated per-app with row-level security (RLS) policies
BackupsDaily encrypted snapshots, 30-day retention
Uptime SLA99.9% target — see /status for live status
🛡️
Access Control
AuthenticationSSO (Google OAuth 2.0) + email/password with 2FA optional
Row-Level SecurityUsers can only read/write their own records. Admin role required for system-level operations.
API keysHashed with bcrypt before storage. Prefix-only shown after creation.
Rate limitingPer-key, configurable 60 req/min default
📋
Compliance
GDPRData processor under EU GDPR. DPA available on request.
Data residencyAll personal data stored in EU (Frankfurt). No US data transfer by default.
SOC 2 Type IIIn progress — target Q4 2026
C2PACompliant with C2PA 1.3 specification. C2PA is a trademark of the Coalition for Content Provenance and Authenticity.
EU AI ActAI Intelligence Layer (Layer 5) outputs raw technical signals only. No automated decisions. Transparency-compliant.
🔍
Penetration Testing
Last pen testScheduled Q3 2026 — report available to Enterprise clients under NDA
Vulnerability disclosuresecurity@truthsource.pro — 72h response SLA
Bug bountyResponsible disclosure program — contact us for scope
📄
Data Processing Agreement
Enterprise and Pro users can request a signed Data Processing Agreement (DPA) for GDPR Article 28 compliance. The DPA covers:
✓Subject-matter and duration of processing
✓Nature and purpose of processing
✓Type of personal data and categories of data subjects
✓Obligations and rights of the controller