Security & data handling

Last updated: 12 July 2026

You are trusting us with compliance-sensitive information. Here is what we collect, where it goes, and how long we keep it.

Assurance scope

The controls below are implementation claims backed by automated tests, internal smoke checks, or operational owner notes. They are not an external security assessment, penetration test, SOC report, certification, or legal opinion unless explicitly stated.

Where your data goes

1. Risk checker stays in your browser

Answers are classified client-side. Nothing is transmitted unless you request email, submit a consultant request, purchase a pack, or activate Monitoring.

2. Submitted records use Postgres

Postgres stores durable customers, leads, orders, documents, subscriptions, access codes, audit logs, rate limits, and short-lived locks. Redis/Upstash is optional and not required for paid self-serve when Postgres is configured.

3. Paid flows are verified through Paddle

Doc Pack and Monitoring entitlements are created only from Paddle-confirmed product, price, amount, currency, and status. Paddle handles card data and tax invoices.

4. Optional AI assist uses Groq

If enabled, AI assist sends only the field you choose after explicit consent. Do not include secrets in that field.

Technical controls

This table focuses on control, status, last verified date, and owner. Internal test evidence is listed separately in the technical assurance appendix.

ControlStatusImplementationLast verifiedOwner
HSTSImplemented and covered by automated testsGlobal Strict-Transport-Security header uses max-age=63072000 with includeSubDomains and preload.12 July 2026TrustPacket operator
Content Security PolicyImplemented and covered by automated testsGlobal CSP restricts sources, blocks objects, sets base-uri/form-action to self, and uses frame-ancestors 'self'.12 July 2026TrustPacket operator
frame-ancestorsImplemented and covered by automated testsMain application pages use frame-ancestors 'self'. The /embed route has a deliberate iframe exception.12 July 2026TrustPacket operator
X-Content-Type-OptionsImplemented and covered by automated testsGlobal X-Content-Type-Options is set to nosniff.12 July 2026TrustPacket operator
Referrer-PolicyImplemented and covered by automated testsGlobal referrer policy is strict-origin-when-cross-origin; private docs and admin API responses use no-referrer.12 July 2026TrustPacket operator
Permissions-PolicyImplemented and covered by automated testsCamera, microphone, and geolocation are disabled by default.12 July 2026TrustPacket operator
Private response cachingImplemented and covered by automated testsDocs, downloads, and admin API responses use no-store and noindex headers.12 July 2026TrustPacket operator
Cookie flagsImplemented and covered by automated testsDoc access and admin session cookies are HttpOnly, SameSite=Lax, path scoped, and Secure in production.12 July 2026TrustPacket operator
CORSImplemented with internal smoke checkNo broad Access-Control-Allow-Origin policy is configured for JSON APIs; browser clients use same-origin requests.12 July 2026TrustPacket operator
CSRFApp-level control covered by automated testsState-changing APIs use JSON schemas, SameSite=Lax cookies, no broad CORS, and server-side entitlement checks.12 July 2026TrustPacket operator
Rate limiting and brute-force protectionImplemented and covered by automated testsLead, access-code, admin login, checkout, document generation, Monitoring, and assist endpoints use rate limits.12 July 2026TrustPacket operator
Access-code entropyImplemented and covered by automated testsOrder tokens and magic links use 32 bytes of cryptographic randomness, hashed lookup, and short expirations.12 July 2026TrustPacket operator
IDOR and order-token enumerationImplemented and covered by automated testsDocs, downloads, regeneration, and Monitoring activation require token/session ownership or signed short-lived links.12 July 2026TrustPacket operator
Signed downloadsImplemented and covered by automated testsWord downloads can use signed 5-minute links and otherwise require verified document access.12 July 2026TrustPacket operator
Paddle webhook signature and replay protectionImplemented and covered by automated testsWebhook processing verifies Paddle signatures, rejects stale signatures, records event IDs, and handles duplicate events idempotently.12 July 2026TrustPacket operator
Source map exposureImplemented and covered by automated testsProduction browser source maps and server source maps are explicitly disabled.12 July 2026TrustPacket operator
Error log PIIOperational taskApplication errors avoid card data because Paddle handles cards; operational log review is still required for questionnaire/support PII.Pending operational evidenceTrustPacket operator + provider dashboard
Backup restoreOperational taskManaged Postgres backup settings must be enabled and restore-tested in the database provider account.Pending operational evidenceTrustPacket operator + provider dashboard
Database row-level authorizationNot claimedCustomers do not receive direct database access. TrustPacket currently relies on route-level authorization, not database RLS.Not claimedTrustPacket operator

Disclosure and assurance

Security contact

Active

Reports go to hello@trustpacket.app. A security.txt file is published for automated discovery.

Vulnerability disclosure policy

Published

Good-faith reports are welcome. Do not access customer data, disrupt service, social-engineer users, or attempt extortion.

Status page

Manual page published

The status page is a manual incident summary, not an automated uptime monitor or SLA.

Data processing addendum

Available on request

A signed DPA is available for paid customers where needed. It is not posted as a generic public contract yet.

Last external security assessment

Not yet completed

No independent penetration test or external security certification is claimed on this page.

Public header scan

Internal smoke checked

Security headers and source-map exposure were last checked by automated smoke tests on 12 July 2026. A third-party public scan is not claimed yet.

Backup restore drill

Pending provider-side evidence

Managed database backups are an operational dependency; the first documented restore drill is still pending.

Incident response summary

Owner assigned

Security reports are triaged by the TrustPacket operator with a target first human response within one business day.

Exact data regions

Published below

The subprocessor table lists provider, purpose, region, transfer basis, backup posture, and support access.

Our commitments

Minimal collection by design

The free checker runs in your browser. We only store data you submit for email, Doc Pack delivery, Monitoring, billing, support, security, or audit needs.

No model training on your inputs

Classification is rule-based code and document generation is deterministic templating. Optional AI assist sends a single field only after explicit consent and is used to polish wording, not to train TrustPacket models.

Paddle handles card data

Paddle is merchant of record for payments, taxes, invoices, refunds, and chargebacks. TrustPacket stores payment status and identifiers, not card numbers.

Short-lived access controls

Requested access codes expire after 15 minutes; initial delivery codes expire after 24 hours.

Retention is explicit

Leads and checker submissions are retained for 90 days by default unless you opt in to ongoing updates. Doc Pack inputs and generated documents are retained for service and support; deletion requests are completed within 72 hours except Paddle tax and invoice records. Public compliance pages remain visible during a 30-day grace period after cancellation or pause.

Encryption and no-store responses

Traffic is served over TLS, provider storage is encrypted at rest, and docs/download responses use no-store headers so private output is not cached by shared browsers or proxies.

Sub-processors

These are the providers that may process product data, depending on which features you use. This table reflects the current production deployment profile without exposing secret values, connection strings, or dashboard credentials.

Provider / servicePurposeDataRegionTransfer / backup / access
VercelVercel Inc. - hosting, serverless functions, static asset delivery, edge network.Hosting, serverless functions, and static asset delivery.HTTP requests, IP metadata, user-agent, server logs, static assets.Vercel Functions: iad1 (Washington, D.C., USA). Static assets and CDN responses may be served from Vercel's global edge network.Vercel DPA/subprocessors and SCCs where restricted transfers apply; traffic may traverse Vercel CDN/edge locations.Static deployment artifacts are replicated under Vercel deployment controls; no TrustPacket document database backup is stored in Vercel.Operator support/admin access may occur from Vietnam with role-limited dashboard access.
NeonNeon managed Postgres (via Vercel Storage integration).Durable application records, rate limits, short-lived locks, customers, orders, subscriptions, leads, access codes, and audit logs.Customer emails, questionnaire answers, generated document records, payment/subscription identifiers, access-code hashes, audit events, rate-limit counters.AWS US East (N. Virginia) - Neon region us-east-1.Neon platform terms/DPA and subprocessors; restricted transfers rely on SCCs where applicable, with TLS in transit and encryption at rest.Neon provider-managed restore/backup data for the database project; no separate TrustPacket backup replica is configured.Operator support/admin access may occur from Vietnam with role-limited dashboard access.
ResendResend - transactional email delivery.Transactional email delivery for checklists, access links, receipts, and admin links.Email address, email body, access links/codes, delivery metadata.United States primary processing operations for email delivery.Resend DPA/subprocessors and EU SCCs for ex-EEA transfers where applicable.Resend-managed delivery logs and metadata under its service settings; no separate TrustPacket email backup is configured.TrustPacket operator access to delivery status in the Resend dashboard.
PaddlePaddle - merchant of record for checkout, billing, tax invoices, refunds, and chargebacks.Payments, subscriptions, receipts, taxes, refunds, and invoices as merchant of record.Buyer email, billing details, transaction/subscription identifiers, tax and invoice records. Card numbers are handled by Paddle, not TrustPacket.Paddle merchant-of-record infrastructure and payment subprocessors, including UK, EU, and United States operations as applicable.Paddle merchant-of-record terms/DPA and SCCs for restricted transfers where applicable.Paddle-retained tax, invoice, and payment records under Paddle legal obligations.TrustPacket can view Paddle transaction/subscription status, not raw card numbers.
PlausiblePlausible Analytics - cookie-free web analytics.Cookie-free product analytics.Page views, referrers, device/browser aggregates, anonymized analytics metadata.Germany (EU-owned infrastructure).EEA processing for visitor analytics; Plausible does not store raw IP addresses or user-agent strings.Plausible-managed analytics retention/backups in Germany/EU infrastructure.TrustPacket operator access to aggregate analytics dashboard.
GroqGroq API - optional AI assist provider.Only used when AI assist is enabled.Optional AI assist for polishing a field when the user explicitly consents.Only the single text field submitted to AI assist; users are instructed not to include secrets.United States. Retained customer data is stored in GCP buckets in the US; inference customer data is not retained by default.Explicit user consent for optional AI assist plus Groq DPA/SCCs where applicable; no TrustPacket model training.No TrustPacket backup. Groq may retain limited reliability and abuse-prevention logs up to 30 days unless zero-data-retention terms apply.TrustPacket does not provide Groq with broad account access to customer documents.

Vulnerability disclosure policy

Send reports to hello@trustpacket.app. Include the affected URL, steps to reproduce, impact, and whether any customer data may have been exposed.

Good-faith testing is allowed only on accounts and data you control. Do not access, modify, delete, or exfiltrate other users' data; do not run denial-of-service tests; do not social-engineer users or providers; and do not publicly disclose before we have had a reasonable opportunity to investigate.

TrustPacket does not currently run a paid bug bounty program. We will acknowledge credible reports and coordinate remediation in good faith.

Technical assurance appendix

Technical buyers sometimes ask which checks back the public controls. These are internal automated tests or smoke scripts, not external audit evidence.

ControlInternal evidence
HSTSCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
Content Security PolicyCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
frame-ancestorsCovered by tests/lib/security-headers.test.ts.
X-Content-Type-OptionsCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
Referrer-PolicyCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
Permissions-PolicyCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
Private response cachingCovered by tests/lib/security-headers.test.ts and API/action tests.
Cookie flagsCovered by tests/lib/pack-access.test.ts and route tests.
CORSscripts/security-smoke.mjs checks that API responses do not expose wildcard CORS.
CSRFCovered by API tests for entitlement, session, and token-gated routes.
Rate limiting and brute-force protectionCovered by API tests and strict launch verification for required storage configuration.
Access-code entropyCovered by tests/lib/pack-access.test.ts and access route tests.
IDOR and order-token enumerationCovered by pack access and pack document action API tests.
Signed downloadsCovered by tests/api/pack-doc-actions.test.ts.
Paddle webhook signature and replay protectionCovered by tests/lib/paddle-signature.test.ts and tests/api/paddle-webhook.test.ts.
Source map exposureCovered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs.
Error log PIIRequires periodic production log review by the operator.
Backup restoreRequires a documented restore drill outside application code.
Database row-level authorizationRoute-level authorization is covered by app tests; DB RLS is not represented as enabled.

How to delete your data

Email hello@trustpacket.app from the address you used, with the subject "Data deletion request". We delete TrustPacket-controlled lead records, questionnaire input, generated documents, access codes, and support metadata within 72 hours where deletion is technically possible.

Paddle retains payment, tax, and invoice records as merchant of record under its own legal obligations.

What we do not claim

TrustPacket is a software product for self-assessment templates and monitoring. It does not replace counsel, notified bodies, conformity assessments, or your internal review.

Questions before buying? Email us. A human replies, usually within one business day.