Trust Center

Procurement proof for safe cloud savings.

Security, privacy and operational resources for teams evaluating TurboFinOps. Claims here are intentionally limited to artifacts that exist today.

Security architecture

Tenant isolation, encrypted credentials, RBAC and guarded action execution.

Open

Data handling

What TurboFinOps processes, what it avoids, and retention expectations.

Open

Subprocessors

Current service providers used for auth, hosting, queues, billing and email.

Open

System status

Live public readiness view for the API and core dependencies.

Open

Incident response

Severity classification, customer notification SLAs and breach notification commitments.

Open

Vulnerability disclosure

How to report security issues, response targets and safe-harbor terms.

Open

Business continuity

Backup strategy, recovery objectives (RPO/RTO) and restore-test cadence.

Open

Service level agreement

Availability targets, measurement methodology, credit schedule and exclusions.

Open

Responsible AI

BYOAI model, data flow, training stance and provider controls.

Open

Security questionnaire

Plain-language answers for CAIQ Lite / SIG Lite topics, plus IAM policy downloads.

Open

Customer proof

Realistic proof workflow without invented customer names or unsupported claims.

Open

Security posture

Tenant isolation

Every tenant data query is scoped to organizationId or protected by RLS context.

Credential protection

Cloud and AI credentials are encrypted at rest and never returned in API responses.

Safe remediation

Actions require conflict checks and default to manual approval.

Audit evidence

State-changing workflows create audit records and evidence artifacts.

SSO and SCIM

Enterprise identity controls support SAML/SSO and SCIM provisioning.

Dependency checks

CI includes production dependency audit gates.

Compliance status

AreaStatusNote
SOC 2 Type IIRoadmap — readiness phaseNot certified. Internal control mapping and evidence flows are implemented in-product. External auditor engagement targeted in 2026.
ISO 27001Roadmap — control mappingNot certified. Product maps findings to ISO 27001 Annex A controls. Formal certification follows SOC 2.
GDPRImplementedData controller and processor terms in /privacy and /legal/dpa. Includes SCCs and the UK IDTA. EU residency by default.
DPAAvailableEnterprise customers can review and execute the DPA from the dashboard. Public summary at /legal/dpa.
Penetration testingPlannedExternal engagement scheduled as part of SOC 2 readiness. Attestation letter available to Enterprise customers under NDA when complete.
Security reviewAvailablePublic security questionnaire at /security/questionnaire. Custom CAIQ/SIG responses on request.

This page avoids unverified certification claims. Signed customer terms control any final legal or compliance commitments.

Compliance roadmap

We publish what is done, what is in progress and what is planned. Items move only when their evidence exists. Target dates for audit-dependent milestones are deliberately not published until the auditor engagement is locked, to avoid implying certification.

  1. Done

    Internal control framework defined

    Rule-to-control mappings for SOC 2 CC and ISO 27001 Annex A surfaces published in /api/v1/compliance/controls.

  2. Done

    Automated tenant-isolation regression suite

    CI gates block release if cross-tenant access is detected.

  3. Done

    Vulnerability disclosure policy

    Public policy and response SLAs at /security/vulnerability-disclosure.

  4. Done

    Incident response policy and 72-hour notification

    Customer notice commitment aligned with GDPR Art. 33.

  5. In progress

    Business continuity and DR with restore tests

    Documented RPO/RTO of ≤ 24 h. Quarterly restore tests rolling out.

  6. Planned

    External penetration test

    Engagement targeted ahead of SOC 2 audit window.

  7. Planned

    SOC 2 Type II audit

    Auditor selection in progress. Customer-facing letter on completion.

  8. Planned

    ISO 27001 certification

    Sequenced after SOC 2 to reuse the audited control framework.

Procurement and security review

A public security questionnaire aligned with CAIQ Lite and SIG Lite topics is available at /security/questionnaire. For custom vendor questionnaires, email support@turbofinops.com. NDA available before sharing detailed architecture, key-management and insurance information.

Get started

Find recoverable spend before the next invoice lands.

Connect one AWS, Azure or GCP scope, approve the safest savings actions, and give finance a receipt when the savings verify.

Read-only scan first. Approval gates before remediation.