Security & data handling
Last updated: 12 July 2026
You are trusting us with compliance-sensitive information. Here is what we collect, where it goes, and how long we keep it.
Assurance scope
The controls below are implementation claims backed by automated tests, internal smoke checks, or operational owner notes. They are not an external security assessment, penetration test, SOC report, certification, or legal opinion unless explicitly stated.
Where your data goes
1. Risk checker stays in your browser
Answers are classified client-side. Nothing is transmitted unless you request email, submit a consultant request, purchase a pack, or activate Monitoring.
2. Submitted records use Postgres
Postgres stores durable customers, leads, orders, documents, subscriptions, access codes, audit logs, rate limits, and short-lived locks. Redis/Upstash is optional and not required for paid self-serve when Postgres is configured.
3. Paid flows are verified through Paddle
Doc Pack and Monitoring entitlements are created only from Paddle-confirmed product, price, amount, currency, and status. Paddle handles card data and tax invoices.
4. Optional AI assist uses Groq
If enabled, AI assist sends only the field you choose after explicit consent. Do not include secrets in that field.
Technical controls
This table focuses on control, status, last verified date, and owner. Internal test evidence is listed separately in the technical assurance appendix.
| Control | Status | Implementation | Last verified | Owner |
|---|---|---|---|---|
| HSTS | Implemented and covered by automated tests | Global Strict-Transport-Security header uses max-age=63072000 with includeSubDomains and preload. | 12 July 2026 | TrustPacket operator |
| Content Security Policy | Implemented and covered by automated tests | Global CSP restricts sources, blocks objects, sets base-uri/form-action to self, and uses frame-ancestors 'self'. | 12 July 2026 | TrustPacket operator |
| frame-ancestors | Implemented and covered by automated tests | Main application pages use frame-ancestors 'self'. The /embed route has a deliberate iframe exception. | 12 July 2026 | TrustPacket operator |
| X-Content-Type-Options | Implemented and covered by automated tests | Global X-Content-Type-Options is set to nosniff. | 12 July 2026 | TrustPacket operator |
| Referrer-Policy | Implemented and covered by automated tests | Global referrer policy is strict-origin-when-cross-origin; private docs and admin API responses use no-referrer. | 12 July 2026 | TrustPacket operator |
| Permissions-Policy | Implemented and covered by automated tests | Camera, microphone, and geolocation are disabled by default. | 12 July 2026 | TrustPacket operator |
| Private response caching | Implemented and covered by automated tests | Docs, downloads, and admin API responses use no-store and noindex headers. | 12 July 2026 | TrustPacket operator |
| Cookie flags | Implemented and covered by automated tests | Doc access and admin session cookies are HttpOnly, SameSite=Lax, path scoped, and Secure in production. | 12 July 2026 | TrustPacket operator |
| CORS | Implemented with internal smoke check | No broad Access-Control-Allow-Origin policy is configured for JSON APIs; browser clients use same-origin requests. | 12 July 2026 | TrustPacket operator |
| CSRF | App-level control covered by automated tests | State-changing APIs use JSON schemas, SameSite=Lax cookies, no broad CORS, and server-side entitlement checks. | 12 July 2026 | TrustPacket operator |
| Rate limiting and brute-force protection | Implemented and covered by automated tests | Lead, access-code, admin login, checkout, document generation, Monitoring, and assist endpoints use rate limits. | 12 July 2026 | TrustPacket operator |
| Access-code entropy | Implemented and covered by automated tests | Order tokens and magic links use 32 bytes of cryptographic randomness, hashed lookup, and short expirations. | 12 July 2026 | TrustPacket operator |
| IDOR and order-token enumeration | Implemented and covered by automated tests | Docs, downloads, regeneration, and Monitoring activation require token/session ownership or signed short-lived links. | 12 July 2026 | TrustPacket operator |
| Signed downloads | Implemented and covered by automated tests | Word downloads can use signed 5-minute links and otherwise require verified document access. | 12 July 2026 | TrustPacket operator |
| Paddle webhook signature and replay protection | Implemented and covered by automated tests | Webhook processing verifies Paddle signatures, rejects stale signatures, records event IDs, and handles duplicate events idempotently. | 12 July 2026 | TrustPacket operator |
| Source map exposure | Implemented and covered by automated tests | Production browser source maps and server source maps are explicitly disabled. | 12 July 2026 | TrustPacket operator |
| Error log PII | Operational task | Application errors avoid card data because Paddle handles cards; operational log review is still required for questionnaire/support PII. | Pending operational evidence | TrustPacket operator + provider dashboard |
| Backup restore | Operational task | Managed Postgres backup settings must be enabled and restore-tested in the database provider account. | Pending operational evidence | TrustPacket operator + provider dashboard |
| Database row-level authorization | Not claimed | Customers do not receive direct database access. TrustPacket currently relies on route-level authorization, not database RLS. | Not claimed | TrustPacket operator |
Disclosure and assurance
Security contact
ActiveReports go to hello@trustpacket.app. A security.txt file is published for automated discovery.
Vulnerability disclosure policy
PublishedGood-faith reports are welcome. Do not access customer data, disrupt service, social-engineer users, or attempt extortion.
Status page
Manual page publishedThe status page is a manual incident summary, not an automated uptime monitor or SLA.
Data processing addendum
Available on requestA signed DPA is available for paid customers where needed. It is not posted as a generic public contract yet.
Last external security assessment
Not yet completedNo independent penetration test or external security certification is claimed on this page.
Public header scan
Internal smoke checkedSecurity headers and source-map exposure were last checked by automated smoke tests on 12 July 2026. A third-party public scan is not claimed yet.
Backup restore drill
Pending provider-side evidenceManaged database backups are an operational dependency; the first documented restore drill is still pending.
Incident response summary
Owner assignedSecurity reports are triaged by the TrustPacket operator with a target first human response within one business day.
Exact data regions
Published belowThe subprocessor table lists provider, purpose, region, transfer basis, backup posture, and support access.
Our commitments
Minimal collection by design
The free checker runs in your browser. We only store data you submit for email, Doc Pack delivery, Monitoring, billing, support, security, or audit needs.
No model training on your inputs
Classification is rule-based code and document generation is deterministic templating. Optional AI assist sends a single field only after explicit consent and is used to polish wording, not to train TrustPacket models.
Paddle handles card data
Paddle is merchant of record for payments, taxes, invoices, refunds, and chargebacks. TrustPacket stores payment status and identifiers, not card numbers.
Short-lived access controls
Requested access codes expire after 15 minutes; initial delivery codes expire after 24 hours.
Retention is explicit
Leads and checker submissions are retained for 90 days by default unless you opt in to ongoing updates. Doc Pack inputs and generated documents are retained for service and support; deletion requests are completed within 72 hours except Paddle tax and invoice records. Public compliance pages remain visible during a 30-day grace period after cancellation or pause.
Encryption and no-store responses
Traffic is served over TLS, provider storage is encrypted at rest, and docs/download responses use no-store headers so private output is not cached by shared browsers or proxies.
Sub-processors
These are the providers that may process product data, depending on which features you use. This table reflects the current production deployment profile without exposing secret values, connection strings, or dashboard credentials.
| Provider / service | Purpose | Data | Region | Transfer / backup / access |
|---|---|---|---|---|
| VercelVercel Inc. - hosting, serverless functions, static asset delivery, edge network. | Hosting, serverless functions, and static asset delivery. | HTTP requests, IP metadata, user-agent, server logs, static assets. | Vercel Functions: iad1 (Washington, D.C., USA). Static assets and CDN responses may be served from Vercel's global edge network. | Vercel DPA/subprocessors and SCCs where restricted transfers apply; traffic may traverse Vercel CDN/edge locations.Static deployment artifacts are replicated under Vercel deployment controls; no TrustPacket document database backup is stored in Vercel.Operator support/admin access may occur from Vietnam with role-limited dashboard access. |
| NeonNeon managed Postgres (via Vercel Storage integration). | Durable application records, rate limits, short-lived locks, customers, orders, subscriptions, leads, access codes, and audit logs. | Customer emails, questionnaire answers, generated document records, payment/subscription identifiers, access-code hashes, audit events, rate-limit counters. | AWS US East (N. Virginia) - Neon region us-east-1. | Neon platform terms/DPA and subprocessors; restricted transfers rely on SCCs where applicable, with TLS in transit and encryption at rest.Neon provider-managed restore/backup data for the database project; no separate TrustPacket backup replica is configured.Operator support/admin access may occur from Vietnam with role-limited dashboard access. |
| ResendResend - transactional email delivery. | Transactional email delivery for checklists, access links, receipts, and admin links. | Email address, email body, access links/codes, delivery metadata. | United States primary processing operations for email delivery. | Resend DPA/subprocessors and EU SCCs for ex-EEA transfers where applicable.Resend-managed delivery logs and metadata under its service settings; no separate TrustPacket email backup is configured.TrustPacket operator access to delivery status in the Resend dashboard. |
| PaddlePaddle - merchant of record for checkout, billing, tax invoices, refunds, and chargebacks. | Payments, subscriptions, receipts, taxes, refunds, and invoices as merchant of record. | Buyer email, billing details, transaction/subscription identifiers, tax and invoice records. Card numbers are handled by Paddle, not TrustPacket. | Paddle merchant-of-record infrastructure and payment subprocessors, including UK, EU, and United States operations as applicable. | Paddle merchant-of-record terms/DPA and SCCs for restricted transfers where applicable.Paddle-retained tax, invoice, and payment records under Paddle legal obligations.TrustPacket can view Paddle transaction/subscription status, not raw card numbers. |
| PlausiblePlausible Analytics - cookie-free web analytics. | Cookie-free product analytics. | Page views, referrers, device/browser aggregates, anonymized analytics metadata. | Germany (EU-owned infrastructure). | EEA processing for visitor analytics; Plausible does not store raw IP addresses or user-agent strings.Plausible-managed analytics retention/backups in Germany/EU infrastructure.TrustPacket operator access to aggregate analytics dashboard. |
| GroqGroq API - optional AI assist provider.Only used when AI assist is enabled. | Optional AI assist for polishing a field when the user explicitly consents. | Only the single text field submitted to AI assist; users are instructed not to include secrets. | United States. Retained customer data is stored in GCP buckets in the US; inference customer data is not retained by default. | Explicit user consent for optional AI assist plus Groq DPA/SCCs where applicable; no TrustPacket model training.No TrustPacket backup. Groq may retain limited reliability and abuse-prevention logs up to 30 days unless zero-data-retention terms apply.TrustPacket does not provide Groq with broad account access to customer documents. |
Vulnerability disclosure policy
Send reports to hello@trustpacket.app. Include the affected URL, steps to reproduce, impact, and whether any customer data may have been exposed.
Good-faith testing is allowed only on accounts and data you control. Do not access, modify, delete, or exfiltrate other users' data; do not run denial-of-service tests; do not social-engineer users or providers; and do not publicly disclose before we have had a reasonable opportunity to investigate.
TrustPacket does not currently run a paid bug bounty program. We will acknowledge credible reports and coordinate remediation in good faith.
Technical assurance appendix
Technical buyers sometimes ask which checks back the public controls. These are internal automated tests or smoke scripts, not external audit evidence.
| Control | Internal evidence |
|---|---|
| HSTS | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| Content Security Policy | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| frame-ancestors | Covered by tests/lib/security-headers.test.ts. |
| X-Content-Type-Options | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| Referrer-Policy | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| Permissions-Policy | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| Private response caching | Covered by tests/lib/security-headers.test.ts and API/action tests. |
| Cookie flags | Covered by tests/lib/pack-access.test.ts and route tests. |
| CORS | scripts/security-smoke.mjs checks that API responses do not expose wildcard CORS. |
| CSRF | Covered by API tests for entitlement, session, and token-gated routes. |
| Rate limiting and brute-force protection | Covered by API tests and strict launch verification for required storage configuration. |
| Access-code entropy | Covered by tests/lib/pack-access.test.ts and access route tests. |
| IDOR and order-token enumeration | Covered by pack access and pack document action API tests. |
| Signed downloads | Covered by tests/api/pack-doc-actions.test.ts. |
| Paddle webhook signature and replay protection | Covered by tests/lib/paddle-signature.test.ts and tests/api/paddle-webhook.test.ts. |
| Source map exposure | Covered by tests/lib/security-headers.test.ts and scripts/security-smoke.mjs. |
| Error log PII | Requires periodic production log review by the operator. |
| Backup restore | Requires a documented restore drill outside application code. |
| Database row-level authorization | Route-level authorization is covered by app tests; DB RLS is not represented as enabled. |
How to delete your data
Email hello@trustpacket.app from the address you used, with the subject "Data deletion request". We delete TrustPacket-controlled lead records, questionnaire input, generated documents, access codes, and support metadata within 72 hours where deletion is technically possible.
Paddle retains payment, tax, and invoice records as merchant of record under its own legal obligations.
What we do not claim
TrustPacket is a software product for self-assessment templates and monitoring. It does not replace counsel, notified bodies, conformity assessments, or your internal review.
Questions before buying? Email us. A human replies, usually within one business day.
Related reading