Trust
Information Security & Trust
Security is foundational to TrustDesk. This page describes how we protect our own systems, the frameworks we align to, and how to reach us with a security concern.
Last updated: July 23, 2026
1. Our commitment to security
TrustDesk is built security-first. We apply a defense-in-depth approach across our people, processes, and technology to protect the platform and the data our customers entrust to us.
2. Governance and compliance
Our security program is aligned to leading frameworks and regulations, including ISO 27001, SOC 2, PCI DSS, the EU/UK GDPR, and India’s DPDP and CERT-In guidance.
We operate documented policies, assign clear ownership, and review our controls on a regular basis.
3. Technical controls
Data is encrypted in transit and at rest. Access is governed by role-based access control and multi-factor authentication, with least-privilege principles applied throughout.
We use network segmentation, continuous logging and monitoring, and regular vulnerability scanning and independent penetration testing.
4. Operational practices
Personnel are vetted and receive ongoing security and privacy training. We follow formal change management, and we maintain 24/7 monitoring and an incident response process.
5. Data protection and privacy
We collect and retain only the data we need, honor data subject rights, and process customer content strictly under our Data Processing Addendum. See our Privacy Policy for details.
6. Resilience and continuity
We maintain backups, business continuity, and disaster recovery practices designed to keep the service available and to restore operations quickly in the event of disruption.
7. Reporting a security concern
To report a security concern or suspected vulnerability, contact security@trustdesk.com. Researchers should also review our Responsible Disclosure Policy.