Security

Last updated: July 8, 2026

Plainly stated, including what we do not have. TrustPages is operated by one person and holds no third-party certification — if your review requires SOC 2 or ISO 27001, we do not meet that bar today and would rather you knew now.

What we hold

Account email addresses, the URLs you asked us to monitor, the change records and page snapshots we captured, the email addresses of people who subscribe to your trust page, and the recipients you enter for change notices. No card details: Paddle is the merchant of record and handles payment data entirely.

Access and authentication

Sign-in is passwordless — a signed, single-use, time-limited link to your email address — so there is no password of yours for us to leak. Sessions are HttpOnly, Secure cookies valid for up to 30 days. Every database query that touches account data is scoped to your account, and the administrative view is limited to a fixed list of addresses.

In transit and at rest

HTTPS everywhere, and a TLS-only database connection. Data is stored in the EU (Frankfurt). Secrets live in the hosting platform's environment configuration, never in the source repository.

Fetching other people's pages

Every URL we fetch is checked before the request and again at every redirect hop, so a page cannot redirect us into a private network or a cloud metadata endpoint. The public directory honours robots.txt — see TrustPagesBot.

Knowing when we are broken

The failure that matters most for a monitoring product is monitoring that stops without saying so. /healthz/monitoring reports the age of the last completed monitoring cycle and returns an error status once it is overdue — you can point your own uptime monitor at it rather than taking our word for it. Individual sources that go unread raise an email alert and carry a visible badge in the dashboard.

Reporting something

Email support@usetrustpages.com with "security" in the subject. We will acknowledge within 72 hours. We do not run a paid bounty; we will credit you if you want the credit, and we will not pursue anyone who reports a problem in good faith without accessing other people's data or degrading the service.

What we do not have

No SOC 2 or ISO 27001 certification. No uptime SLA, and no 24/7 on-call. No penetration test by a third party. Single-region hosting with no hot standby. If any of that is a blocker for your review, it is a real blocker — say so and we will tell you honestly whether it is on the roadmap.

Last updated: 2 September 2026.