Security, privacy and operational resources for teams evaluating TurboFinOps. Claims here are intentionally limited to artifacts that exist today.
Tenant isolation, encrypted credentials, RBAC and guarded action execution.
OpenWhat TurboFinOps processes, what it avoids, and retention expectations.
OpenCurrent service providers used for auth, hosting, queues, billing and email.
OpenLive public readiness view for the API and core dependencies.
OpenSeverity classification, customer notification SLAs and breach notification commitments.
OpenHow to report security issues, response targets and safe-harbor terms.
OpenBackup strategy, recovery objectives (RPO/RTO) and restore-test cadence.
OpenAvailability targets, measurement methodology, credit schedule and exclusions.
OpenBYOAI model, data flow, training stance and provider controls.
OpenPlain-language answers for CAIQ Lite / SIG Lite topics, plus IAM policy downloads.
OpenRealistic proof workflow without invented customer names or unsupported claims.
OpenTenant isolation
Every tenant data query is scoped to organizationId or protected by RLS context.
Credential protection
Cloud and AI credentials are encrypted at rest and never returned in API responses.
Safe remediation
Actions require conflict checks and default to manual approval.
Audit evidence
State-changing workflows create audit records and evidence artifacts.
SSO and SCIM
Enterprise identity controls support SAML/SSO and SCIM provisioning.
Dependency checks
CI includes production dependency audit gates.
| Area | Status | Note |
|---|---|---|
| SOC 2 Type II | Roadmap — readiness phase | Not certified. Internal control mapping and evidence flows are implemented in-product. External auditor engagement targeted in 2026. |
| ISO 27001 | Roadmap — control mapping | Not certified. Product maps findings to ISO 27001 Annex A controls. Formal certification follows SOC 2. |
| GDPR | Implemented | Data controller and processor terms in /privacy and /legal/dpa. Includes SCCs and the UK IDTA. EU residency by default. |
| DPA | Available | Enterprise customers can review and execute the DPA from the dashboard. Public summary at /legal/dpa. |
| Penetration testing | Planned | External engagement scheduled as part of SOC 2 readiness. Attestation letter available to Enterprise customers under NDA when complete. |
| Security review | Available | Public security questionnaire at /security/questionnaire. Custom CAIQ/SIG responses on request. |
This page avoids unverified certification claims. Signed customer terms control any final legal or compliance commitments.
We publish what is done, what is in progress and what is planned. Items move only when their evidence exists. Target dates for audit-dependent milestones are deliberately not published until the auditor engagement is locked, to avoid implying certification.
Internal control framework defined
Rule-to-control mappings for SOC 2 CC and ISO 27001 Annex A surfaces published in /api/v1/compliance/controls.
Automated tenant-isolation regression suite
CI gates block release if cross-tenant access is detected.
Vulnerability disclosure policy
Public policy and response SLAs at /security/vulnerability-disclosure.
Incident response policy and 72-hour notification
Customer notice commitment aligned with GDPR Art. 33.
Business continuity and DR with restore tests
Documented RPO/RTO of ≤ 24 h. Quarterly restore tests rolling out.
External penetration test
Engagement targeted ahead of SOC 2 audit window.
SOC 2 Type II audit
Auditor selection in progress. Customer-facing letter on completion.
ISO 27001 certification
Sequenced after SOC 2 to reuse the audited control framework.
A public security questionnaire aligned with CAIQ Lite and SIG Lite topics is available at /security/questionnaire. For custom vendor questionnaires, email support@turbofinops.com. NDA available before sharing detailed architecture, key-management and insurance information.
Connect one AWS, Azure or GCP scope, approve the safest savings actions, and give finance a receipt when the savings verify.