Security at TRULNK

How we protect your business data, your customer conversations, and your trust. Concrete controls, plainly stated — not marketing language.

Infrastructure & encryption

  • TLS 1.2+ everywhere. All traffic between your browser and TRULNK, and between TRULNK and our service providers, is encrypted in transit. HSTS is enforced with a 2-year max-age and preload, so the browser refuses to fall back to plain HTTP.
  • AES-256 encryption at rest. Your database rows, call recordings, transcripts, and uploaded documents are all encrypted on disk by our managed infrastructure providers (Supabase, Vercel, Cloudflare).
  • Integration tokens are doubly encrypted. When you connect an external service (CRM, helpdesk, calendar), the access token is encrypted with AES-256-GCM at the application layer before it ever touches the database — so a database breach alone cannot decrypt them.
  • US-based infrastructure. Compute, database, and storage are all hosted in US data centers. Our self-hosted AI runs in a US colocation facility under our direct control.
  • Cloudflare in front of everything. DDoS protection, bot mitigation, and a Web Application Firewall sit between attackers and our servers.

Authentication & access control

  • Multi-factor authentication is required. Every account must have SMS-based MFA enrolled. There is no opt-out — even for the owner.
  • OAuth via Google and Microsoft is supported for organizations that already have identity providers in place.
  • Strong password policy. Minimum 12 characters with mixed case, numbers, and symbols. Compared in constant time to prevent timing attacks.
  • Row-level security on every database table. Each query is scoped to the authenticated organization at the database layer — not just in application code. Even if our application had a bug, the database would refuse cross-organization access.
  • Session management. Industry-standard JWT with rolling refresh tokens. You can sign out other devices any time from My Account.
  • Audit logging. Every privileged action — sign-in, password change, data export, admin access, settings modification — is recorded with timestamp, IP address, and user agent. Available to you in the My Account activity log.

AI & data privacy

  • Self-hosted AI. The language models that power your AI agents run on hardware we own and operate — not on a third-party API. Your calls, texts, and emails are never sent to OpenAI, Anthropic, Google, or any other AI vendor.
  • No training on your data — unless you opt in. By default, your recordings, transcripts, messages, and business information are never used to train AI models. The AI Improvement Program is off by default, opt-in only, revocable at any time, and strips direct identifiers before anything is used; even then, training happens on our own hardware, never at a third-party vendor.
  • Phone numbers masked in logs. Any caller phone number written to operational logs shows only the last four digits. Full numbers exist only in the encrypted call records that you control.
  • Configurable retention. You choose how long call recordings and transcripts are kept (default 90 days). Auto-deletion runs daily on the schedule you set.
  • Data export and deletion. Export everything we have on you with one click in My Account. Account deletion cascades through all systems — Stripe, Twilio, integrations — within minutes.

Operational security

  • Continuous monitoring. Wazuh-based intrusion detection, file integrity monitoring, and CVE scanning run on every server. Critical events trigger immediate alerts.
  • Endpoint security. Every workstation that touches production is protected by Microsoft Defender EDR, BitLocker disk encryption, and Intune-managed policy compliance. Linux servers run hardened images with SSH key-only access and LUKS-encrypted volumes.
  • Patch SLA. Critical-severity CVEs are patched within 7 days, high-severity within 14, others within 30. Tracked automatically.
  • Off-site backups. Application database, call recordings, and security event logs are replicated daily to encrypted off-site storage at a separate cloud provider. Restore drills are documented and tested.
  • Incident response plan. Documented procedure with 72-hour breach notification commitment, post-incident reviews, and a published recovery time objective of 4 hours.

Compliance & audits

  • SOC 2 alignment. TRULNK is built to align with SOC 2 Type II Common Criteria (CC1–CC9 plus Availability, Confidentiality, Processing Integrity, and Privacy). We are not currently SOC 2 certified — a formal audit is planned as we grow. Enterprise prospects can request our security packet at security@trulnk.com.
  • GDPR & CCPA. Right to access, right to deletion, and data portability are all implemented as self-service flows in My Account. Our privacy policy lists every category of data we collect and why.
  • PCI-DSS via Stripe. We never see, store, or transmit payment card numbers. Stripe handles all card processing and PCI compliance. When customers pay by phone via DTMF, the digits are processed in memory and never logged.
  • Vendor due diligence. Every subprocessor — Supabase, Stripe, Twilio, Resend — has been reviewed for SOC 2 / ISO 27001 posture and we maintain DPAs where applicable. List available on request.

Reporting a vulnerability

If you believe you've found a security issue, please email security@trulnk.com with details.

What we ask:

  • Describe the issue and how to reproduce it
  • Don't exfiltrate data beyond what's needed to demonstrate the issue
  • Don't run automated scanners that degrade service for other customers
  • Give us a reasonable window to fix before public disclosure (typically 90 days)

What we commit to: we'll acknowledge receipt within 2 business days, give you a fix timeline, keep you informed, and credit you in our advisory if you want.

Security contact
security@trulnk.com
Privacy Policy
What we collect and why
System status
status.trulnk.com
TRULNK — Your AI Workforce