TrustPin™
Security, privacy & compliance

Trust, by
Design

TrustPin is built for the teams who own risk. Here is how we protect your data, what we store (and what we never touch), and the controls and documentation your security review needs.

Security Architecture

Defense-in-depth from the TLS handshake to remote configuration, with trust anchored to keys you control.

Pinning enforced at the TLS handshake

The SDK validates the server's certificate or public key against your pinned set before any application data is exchanged, blocking man-in-the-middle attacks even when an attacker holds a certificate from a compromised CA.

Signed, integrity-checked configuration

Pinning configurations are signed with ECDSA P-256 and verified on-device against a published JWKS; a forged or tampered configuration is rejected. Bring Your Own Keys (BYOK) lets you sign with your own private key so cryptographic trust never leaves your control.

Anti-rollback & offline validation

Devices reject stale or downgraded configurations and continue validating against the last trusted set when offline, so remote updates can never silently weaken your pinning.

Strict and permissive modes

Choose fail-closed (strict) enforcement for production or permissive monitoring during rollout. SHA-256 and SHA-512 pin formats are supported.

Beyond the channel: runtime protection

Certificate pinning secures the connection, but tampering, hooking, and repackaging attack the app itself. For those layers, TrustPin partners with Promon, whose Runtime Application Self-Protection (RASP) and app-shielding technology complements TrustPin's pinning for defense-in-depth. Learn about the partnership →

Data Protection & Privacy

We manage certificates, not your users. The less we hold, the less there is to lose.

No end-user PII

TrustPin collects no application end-user data; like any networked service, CDN edges may transiently process the IP addresses of devices fetching public configuration.

Encrypted in transit and at rest

All connections use TLS 1.2+ with HSTS and Certificate Transparency (A+ SSL Labs rating); data is encrypted at rest. Certificate material is non-secret by design.

EU data residency

Platform data is hosted on EU infrastructure, supporting GDPR data-residency requirements for European customers.

Data minimization & retention

We collect the minimum needed to operate the service and honor deletion requests. See our Privacy Policy for retention specifics.

Privacy by design

What we collect, and what we don't

Two distinct data layers, written out so there is nothing to assume. Our approach follows data-minimization principles inspired by GDPR and CCPA.

TrustPin account holders

For developers and companies who sign up for our platform, we collect minimal personal data (name and email), only to operate the account.

End users of your app

For people using apps that embed our SDK, we collect no identifying data. The metadata we receive cannot single out an individual.

What the SDK actually sends

On each request the SDK sends only non-identifying technical metadata, carried in the User-Agent string:

  • SDK version
  • App bundle ID and app version: identifies the app, not the user
  • OS name and OS version
  • A coarse, continent-level region (Americas / Europe / Asia-Pacific / Africa / Other), derived from the device timezone, not from IP geolocation

What it never sends:

No device IDs, no advertising IDs, no names, no emails, no precise location. TrustPin does not use request IP addresses to identify end users or store them in its application databases; raw CDN access logs that include IPs are retained only briefly for security and anonymous aggregate statistics, then automatically deleted. Because two different users of the same app, OS, and region produce an identical string, this metadata cannot be used to single out an individual end user.

Right to modify these terms

TrustPin may modify these terms and our privacy practices, in whole or in part, at any time. For material changes, we will provide notice at least 30 days before they take effect, by email and/or a notice on this page. Non-material changes, or changes required by law, may take effect immediately. Your continued use of the service after the effective date constitutes acceptance of the updated terms.

Access & Operational Controls

Governance that maps to your internal policies: who can change what, and a record of every change.

Role-based access control

Granular, role-based permissions across organizations and projects.

SSO & OAuth

Single sign-on and OAuth-based authentication (Google, GitHub, and more).

Audit logging

Every configuration change is recorded with an attributable audit trail.

Bring Your Own Keys

Sign configurations with your own keys to meet internal key-management policy.

Standards & Compliance

Our strongest control is scope: we manage certificates, not your users' data. Here is what your due-diligence review can rely on today.

OWASP MASVS alignment

Built to the OWASP Mobile Application Security Verification Standard and Testing Guide.

GDPR & EU data residency

EU-hosted infrastructure with GDPR-aligned data handling and deletion workflows.

No end-user PII processed

We manage certificate configuration only and collect no application end-user data, keeping your regulatory scope small.

Customer-controlled trust (BYOK)

Sign configurations with your own keys so cryptographic trust never leaves your organization.

Need our DPA, sub-processor list, or SLA for your vendor assessment? Request the security package.

Reliability & Availability

Certificate delivery is on the critical path. We engineer for it, and you can verify it.

99.9%

Uptime SLA on paid plans, measured separately for delivery and the management platform, with service credits

Global CDN

Edge-cached configuration delivery worldwide

Live status

Real-time uptime at status.trustpin.cloud

No single point of dependency

Configuration delivery is engineered so your apps never depend on any one component, including us. Three independent layers protect availability:

1

Your CDN, or ours

Use TrustPin's redundant CDNs, or set your own CDN as the primary source with TrustPin as backup, keeping delivery fully in your control.

2

Automatic failover

If one delivery path is unavailable, the SDK transparently falls over to another.

3

Offline-safe

If all delivery is unreachable, deployed apps keep validating against the last trusted configuration, so pinning is never interrupted.

Responsible Disclosure

Security researchers are a vital part of keeping TrustPin safe. If you believe you have found a vulnerability, please report it privately so we can investigate and remediate before any public disclosure. We commit to acknowledging reports promptly and keeping you updated through resolution.

Bring TrustPin to your security review

We will walk your security and compliance teams through our architecture, controls, and documentation. No sales pressure, just answers.