
TrustPin is built for the teams who own risk. Here is how we protect your data, what we store (and what we never touch), and the controls and documentation your security review needs.
Defense-in-depth from the TLS handshake to remote configuration, with trust anchored to keys you control.
The SDK validates the server's certificate or public key against your pinned set before any application data is exchanged, blocking man-in-the-middle attacks even when an attacker holds a certificate from a compromised CA.
Pinning configurations are signed with ECDSA P-256 and verified on-device against a published JWKS; a forged or tampered configuration is rejected. Bring Your Own Keys (BYOK) lets you sign with your own private key so cryptographic trust never leaves your control.
Devices reject stale or downgraded configurations and continue validating against the last trusted set when offline, so remote updates can never silently weaken your pinning.
Choose fail-closed (strict) enforcement for production or permissive monitoring during rollout. SHA-256 and SHA-512 pin formats are supported.
Certificate pinning secures the connection, but tampering, hooking, and repackaging attack the app itself. For those layers, TrustPin partners with Promon, whose Runtime Application Self-Protection (RASP) and app-shielding technology complements TrustPin's pinning for defense-in-depth. Learn about the partnership →
We manage certificates, not your users. The less we hold, the less there is to lose.
TrustPin collects no application end-user data; like any networked service, CDN edges may transiently process the IP addresses of devices fetching public configuration.
All connections use TLS 1.2+ with HSTS and Certificate Transparency (A+ SSL Labs rating); data is encrypted at rest. Certificate material is non-secret by design.
Platform data is hosted on EU infrastructure, supporting GDPR data-residency requirements for European customers.
We collect the minimum needed to operate the service and honor deletion requests. See our Privacy Policy for retention specifics.
Two distinct data layers, written out so there is nothing to assume. Our approach follows data-minimization principles inspired by GDPR and CCPA.
For developers and companies who sign up for our platform, we collect minimal personal data (name and email), only to operate the account.
For people using apps that embed our SDK, we collect no identifying data. The metadata we receive cannot single out an individual.
On each request the SDK sends only non-identifying technical metadata, carried in the User-Agent string:
What it never sends:
No device IDs, no advertising IDs, no names, no emails, no precise location. TrustPin does not use request IP addresses to identify end users or store them in its application databases; raw CDN access logs that include IPs are retained only briefly for security and anonymous aggregate statistics, then automatically deleted. Because two different users of the same app, OS, and region produce an identical string, this metadata cannot be used to single out an individual end user.
TrustPin may modify these terms and our privacy practices, in whole or in part, at any time. For material changes, we will provide notice at least 30 days before they take effect, by email and/or a notice on this page. Non-material changes, or changes required by law, may take effect immediately. Your continued use of the service after the effective date constitutes acceptance of the updated terms.
Governance that maps to your internal policies: who can change what, and a record of every change.
Granular, role-based permissions across organizations and projects.
Single sign-on and OAuth-based authentication (Google, GitHub, and more).
Every configuration change is recorded with an attributable audit trail.
Sign configurations with your own keys to meet internal key-management policy.
Our strongest control is scope: we manage certificates, not your users' data. Here is what your due-diligence review can rely on today.
Built to the OWASP Mobile Application Security Verification Standard and Testing Guide.
EU-hosted infrastructure with GDPR-aligned data handling and deletion workflows.
We manage certificate configuration only and collect no application end-user data, keeping your regulatory scope small.
Sign configurations with your own keys so cryptographic trust never leaves your organization.
Need our DPA, sub-processor list, or SLA for your vendor assessment? Request the security package.
Certificate delivery is on the critical path. We engineer for it, and you can verify it.
Uptime SLA on paid plans, measured separately for delivery and the management platform, with service credits
Edge-cached configuration delivery worldwide
Real-time uptime at status.trustpin.cloud
Configuration delivery is engineered so your apps never depend on any one component, including us. Three independent layers protect availability:
Your CDN, or ours
Use TrustPin's redundant CDNs, or set your own CDN as the primary source with TrustPin as backup, keeping delivery fully in your control.
Automatic failover
If one delivery path is unavailable, the SDK transparently falls over to another.
Offline-safe
If all delivery is unreachable, deployed apps keep validating against the last trusted configuration, so pinning is never interrupted.
Security researchers are a vital part of keeping TrustPin safe. If you believe you have found a vulnerability, please report it privately so we can investigate and remediate before any public disclosure. We commit to acknowledging reports promptly and keeping you updated through resolution.
Report to: security@trustpin.cloud
We will walk your security and compliance teams through our architecture, controls, and documentation. No sales pressure, just answers.