Skip to content
Trust center

Compliance is done. Residency is real.

Trifrost is built for organizations whose security review is a gate, not a formality. Certifications completed, regions live, audit trail signed — evidence over adjectives.

SOC 2 Type II ISO 27001 HIPAA
Certifications

Completed. Not "in progress".

Three frameworks, audited and done. Reports are shared under NDA during your security review.

Completed

SOC 2 Type II

Independent audit of security, availability, and confidentiality controls — over time, not at a point.

Completed

ISO 27001

Certified information security management system covering the Trifrost platform and operations.

Completed

HIPAA

HIPAA-compliant for protected health information. A BAA is available for Enterprise healthcare customers processing PHI.

Data residency

The service runs in your region. Your data stays there.

Five regions live at GA: Australia, APAC, EMEA, United Kingdom, and Germany. Need somewhere else? We stand it up on request. Residency is by construction — the control plane and event store run in-region, so compliance follows from architecture, not policy slides.

  • GDPR & UK Data Protection — EMEA, UK, and Germany regions
  • Australian Privacy Principles — AU region
  • APAC data sovereignty — APAC region
  • Region on request — new regions stood up for Enterprise customers
The Trifrost dashboard overview with request volume, spend, and provider health panels
One control plane, deployed per region
0
REGIONS LIVE AT GA
0
CERTIFICATIONS COMPLETED
1
SIGNED EVENT PER REQUEST
0
CLIENT-SIDE TOKENS
Data protection

Practices you can verify.

Every claim below maps to a behavior you can test from the API surface or inspect in the console.

Encryption everywhere

TLS in transit, encryption at rest. Virtual keys are stored as SHA-256 hashes and compared timing-safe — the plaintext key is never persisted.

Secrets never leak

Provider API keys are never returned by admin reads. The streaming path strips client credentials — cookies, authorization headers, virtual keys — before any request goes upstream.

Server-side sessions only

Admin access runs through OIDC BFF with server-side sessions. No client-side tokens, no master-key escape hatch. Your IdP is the source of truth on every login.

Absolute tenant isolation

Every customer-scoped read is scoped by the session's active customer. Cross-organization access returns 404 — even read-only, even for platform admins.

Fail-closed governance

Budgets, allowlists, and rate limits resolve from an in-memory cache with zero database hits on the hot path. When in doubt, the system denies — it never fails open.

Nothing fails silently

Blocked and denied requests (401/402/403/429/400) produce exactly one signed event row with the reason. A denial is auditable, never invisible.

Tamper-evident audit

Every request — success, failure, blocked, streaming — and every admin mutation lands as exactly one HMAC-SHA256 signed event in a partitioned, append-only log. Mutate a row and the signature breaks. Export to your SIEM as JSON, JSONL, or Syslog RFC 5424.

Explore observability →

Identity your way

Okta, Entra, Keycloak, Zitadel, Google Workspace. The roles claim from your IdP is intersected with team claims on each login to compute department memberships — access changes propagate at next login, not at next audit.

Explore governance →

DPA

A Data Processing Agreement is available for Enterprise customers.

Read the DPA →

Sub-processors

The current list of sub-processors, kept up to date.

View sub-processors →

Responsible disclosure

Found a security issue? We want to hear it before anyone else does.

cory+trifrost@hawkvelt.id.au →

Uptime & status

Current and historical availability is published on our status page. Alias-group load balancing with automatic failover means a single-provider outage doesn't become your outage — the gateway keeps the stream alive.

Security review?

Send us your questionnaire. We'll send back evidence.

SOC 2 Type II · ISO 27001 · HIPAA. BAA available on Enterprise.