Compliance is done. Residency is real.
Trifrost is built for organizations whose security review is a gate, not a formality. Certifications completed, regions live, audit trail signed — evidence over adjectives.
Completed. Not "in progress".
Three frameworks, audited and done. Reports are shared under NDA during your security review.
Completed
SOC 2 Type II
Independent audit of security, availability, and confidentiality controls — over time, not at a point.
Completed
ISO 27001
Certified information security management system covering the Trifrost platform and operations.
Completed
HIPAA
HIPAA-compliant for protected health information. A BAA is available for Enterprise healthcare customers processing PHI.
The service runs in your region. Your data stays there.
Five regions live at GA: Australia, APAC, EMEA, United Kingdom, and Germany. Need somewhere else? We stand it up on request. Residency is by construction — the control plane and event store run in-region, so compliance follows from architecture, not policy slides.
- GDPR & UK Data Protection — EMEA, UK, and Germany regions
- Australian Privacy Principles — AU region
- APAC data sovereignty — APAC region
- Region on request — new regions stood up for Enterprise customers
Practices you can verify.
Every claim below maps to a behavior you can test from the API surface or inspect in the console.
Encryption everywhere
TLS in transit, encryption at rest. Virtual keys are stored as SHA-256 hashes and compared timing-safe — the plaintext key is never persisted.
Secrets never leak
Provider API keys are never returned by admin reads. The streaming path strips client credentials — cookies, authorization headers, virtual keys — before any request goes upstream.
Server-side sessions only
Admin access runs through OIDC BFF with server-side sessions. No client-side tokens, no master-key escape hatch. Your IdP is the source of truth on every login.
Absolute tenant isolation
Every customer-scoped read is scoped by the session's active customer. Cross-organization access returns 404 — even read-only, even for platform admins.
Fail-closed governance
Budgets, allowlists, and rate limits resolve from an in-memory cache with zero database hits on the hot path. When in doubt, the system denies — it never fails open.
Nothing fails silently
Blocked and denied requests (401/402/403/429/400) produce exactly one signed event row with the reason. A denial is auditable, never invisible.
Tamper-evident audit
Every request — success, failure, blocked, streaming — and every admin mutation lands as exactly one HMAC-SHA256 signed event in a partitioned, append-only log. Mutate a row and the signature breaks. Export to your SIEM as JSON, JSONL, or Syslog RFC 5424.
Explore observability →Identity your way
Okta, Entra, Keycloak, Zitadel, Google Workspace. The roles claim from your IdP is intersected with team claims on each login to compute department memberships — access changes propagate at next login, not at next audit.
Explore governance →Responsible disclosure
Found a security issue? We want to hear it before anyone else does.
Uptime & status
Current and historical availability is published on our status page. Alias-group load balancing with automatic failover means a single-provider outage doesn't become your outage — the gateway keeps the stream alive.
Send us your questionnaire. We'll send back evidence.
SOC 2 Type II · ISO 27001 · HIPAA. BAA available on Enterprise.