Home
LEGAL

Security at triffy

Your formation documents, identification details, and payment information deserve real protection. Here's how we handle it, and how to report a concern.

Encryption

Data is encrypted in transit using TLS and at rest using AES-256. Formation documents, identification uploads, and account data are encrypted wherever they are stored.

Infrastructure and access

triffy is hosted on infrastructure with encryption enabled by default. Internal access to customer data is limited to the people who need it to deliver the service, follows least-privilege principles, and is logged.

Payments

Card payments are handled by a PCI-DSS-compliant payment processor. triffy does not store your full card number on its own systems.

Our practices

Our internal controls — change management, vendor review, incident response, and access management — are built around SOC 2 principles. We're working toward formal third-party certification and will publish it here once complete.

Report a vulnerability

If you believe you have found a security issue, please report it to security@triffy.com before disclosing it publicly. Avoid accessing, modifying, or deleting data that is not yours, and do not include sensitive personal information in your initial report — we will follow up for detail. We will not pursue legal action against good-faith, non-destructive security research reported this way.