Security Practices
How we protect you — by design, not by policy.
How your data flows
Your data passes through our pipeline and is immediately discarded. Nothing is ever stored.
Desktop: left to right · Mobile: top to bottom
✓Zero-Storage Architecture
TRUVO360 is built from the ground up to never store user data. This isn’t a privacy policy choice — it’s an architectural decision. There are no databases containing scan results, no search logs, no PII storage. When you run a scan, the data is fetched, analyzed, returned to your browser, and immediately discarded.
✓Infrastructure Security
All connections are encrypted with TLS 1.3. No exceptions.
Deployed on a global edge network with built-in DDoS protection.
No databases to breach. The attack surface is minimal by design.
10 requests per IP per 5-minute window to prevent abuse.
All API keys are stored as encrypted environment variables, never in code.
✓Payment Security
All payments are processed by Stripe, a PCI Level 1 certified payment processor — the highest level of certification in the payments industry. TRUVO360 never sees, processes, or stores your credit card information. Billing details are handled entirely by Stripe’s secure infrastructure.
✓Authentication
Authentication is handled by enterprise-grade infrastructure. We support Google OAuth and email/password login with email verification. Password hashing, session management, and token refresh are all managed securely. We use auth-only session cookies — no tracking or analytics cookies.
✓Compliance
• FCRA: TRUVO360 is not a consumer reporting agency and does not provide background checks as defined by the FCRA.
• GDPR/CCPA: Cookie consent banner with accept/decline. Auth-only essential cookies.
• SOC 2: Our infrastructure providers are SOC 2 Type II certified.
Data Sources We Use
Every source is a legitimate, documented API with terms allowing automated commercial use.
What We DON'T Do
Report a Vulnerability
Found a security issue? We take all reports seriously. Please contact our security team directly.
[email protected]