Trust · Security

Security you can audit.

SAML SSO with SCIM. Every gate cryptographically signed and appended to an immutable log. What follows is what we do, what we don't, and where to send a report.

GDPR ready
SAML · SCIM
AES-256 · TLS 1.3
Immutable audit log
1

Data model

Trunk stores three categories of data:

  • Product content — your primitives (styles, components, pages), deltas, documentation, flags, comments. Encrypted at rest with AES-256, in transit with TLS 1.3.
  • Identity + audit — user records, SSO mappings, gate signatures, activity log. Isolated database, tamper-evident.
  • Repo access tokens — GitHub / GitLab / Bitbucket OAuth tokens. Encrypted, rotated on OAuth-refresh, scope-limited to read + PR-write.

We do not store your source-code repository. Trunk raises PRs on your remote; the code lives with your provider.

2

Access & identity

SAML SSO
Google · Microsoft · Okta on Team. Full SAML · SCIM on Enterprise.
SCIM provisioning
Provision + deprovision users from your IdP. Role changes propagate to gates within 60s.
Session policy
Configurable idle timeout, MFA enforcement, per-role sudo. Session revoke via IdP.
RBAC
Owner · Admin · Designer · Engineer · PM · TL · EM · On-call · Legal · Security · Reviewer · Guest.
3

Audit trail

Every gate signature is cryptographically signed with the signer's SSO identity, timestamped, and appended to an immutable, tamper-evident log. Retention is 30 days on Team, up to 1 year on Enterprise. Export as CSV / JSON via API for regulators.

2026-07-08T14:22:04Z gate.sign phase=Approve delta=#142 signer=chen@acme.com sso=okta:abc sig=sha256:8f2c…

The log is append-only. Deletions are recorded, never applied. A per-tenant Merkle root lets you verify integrity independently.

4

Infrastructure

Multi-tenant SaaS
AWS us-east-1 primary · eu-west-1 replica. Per-tenant DB namespace + KMS key.
Backups
Continuous WAL replication · 15-minute PITR window · nightly encrypted snapshot to cold storage.
5

Subprocessors

ProviderPurposeRegion
AWSPrimary compute + storageus-east-1 · eu-west-1
CloudflareCDN + DDoS mitigationGlobal
StripePayment processingUS · EU
VantaContinuous compliance monitoringUS
6

Reporting vulnerabilities

Report security issues to firodiya.ritesh@gmail.com. PGP key: request by email. We acknowledge within 24 hours, triage within 72, and publicly credit reporters (opt-in) in the trust package.

Please do not run scans against production. If you need to test attack scenarios, contact us for a scoped staging environment.

Security questionnaires
Vanta Trust Center · SIG · CAIQ answered.
Request trust package →