SAML SSO with SCIM. Every gate cryptographically signed and appended to an immutable log. What follows is what we do, what we don't, and where to send a report.
Trunk stores three categories of data:
We do not store your source-code repository. Trunk raises PRs on your remote; the code lives with your provider.
Every gate signature is cryptographically signed with the signer's SSO identity, timestamped, and appended to an immutable, tamper-evident log. Retention is 30 days on Team, up to 1 year on Enterprise. Export as CSV / JSON via API for regulators.
The log is append-only. Deletions are recorded, never applied. A per-tenant Merkle root lets you verify integrity independently.
| Provider | Purpose | Region |
|---|---|---|
| AWS | Primary compute + storage | us-east-1 · eu-west-1 |
| Cloudflare | CDN + DDoS mitigation | Global |
| Stripe | Payment processing | US · EU |
| Vanta | Continuous compliance monitoring | US |
Report security issues to firodiya.ritesh@gmail.com. PGP key: request by email. We acknowledge within 24 hours, triage within 72, and publicly credit reporters (opt-in) in the trust package.
Please do not run scans against production. If you need to test attack scenarios, contact us for a scoped staging environment.