● Trust centre

Trust & Security

Last updated September 2026

Tribastion TI handles sensitive breach-exposure data, so security and privacy are built into the product, not bolted on. This page summarises our certifications, controls and design principles.

🛡️ SOC 2 Type II ⚖️ DPDPA compliant 🔒 Privacy by Design 🔑 Encrypted at rest & in transit 📝 Full audit trail

SOC 2 Type II

Our controls are independently examined against the AICPA SOC 2 Trust Services Criteria over an audit period (Type II). Controls are mapped across the applicable criteria:

CriterionRepresentative controls
Securityrole-based access control (RBAC) with segregation of duties; per-account, rate-limited, credit-metered API keys; strict Content-Security-Policy and security headers; hardened session auth with lockout; secure-SDLC change management.
Availabilityhealth checks, cache-backed hot paths, replicated database backups, cloud file-offload with redundancy.
Confidentialityencryption of secrets and integration credentials at rest (AES); masked-by-default output; least-privilege data access; TLS in transit.
Processing Integritydeterministic collection pipeline with a 48-hour cache, idempotent imports, and an interlink graph rebuilt from source records.
PrivacyDPDPA-aligned notice & consent, data-principal rights intake, retention limits, and a documented grievance process.

A copy of the current SOC 2 Type II report is available to customers under NDA on request.

Privacy by Design

We follow the seven foundational principles of Privacy by Design:

  1. Proactive not reactive — privacy risks are addressed in design and review, before release.
  2. Privacy as the default — passwords and secrets are masked by default; full reveal is a deliberate, per-account entitlement.
  3. Privacy embedded into design — access control, encryption and audit are core architecture, not add-ons.
  4. Full functionality, positive-sum — strong security without sacrificing usability.
  5. End-to-end security — data is protected across its full lifecycle, from collection to deletion.
  6. Visibility & transparency — clear notices, an on-site consent manager, and an auditable trail.
  7. Respect for user privacy — easy consent withdrawal and data-principal rights.

Secure SDLC

Data handling & masking

Exposure output is masked by default across the console and API. Validation of whether a leaked credential still works is performed from the customer’s own authorised position — the platform never uses a recovered credential itself. Connected storage and integration credentials are encrypted and never exposed.

Reporting a vulnerability

If you believe you’ve found a security issue, please contact ASM@tribastion.com. We acknowledge reports promptly and work with reporters in good faith.