This page is for the compliance officer assessing Trusset as a vendor. After reading it you will know which certifications are complete, which are still in progress, and where to find the underlying documentation.
DORA, ISO, TÜV, GDPR, and audit documentation
Trusset provides a searchable database of regularly updated compliance documents. Those documents are currently being reviewed by TÜV as part of the final certification process. You can find the database in the Issuer App under “Compliance Data Room”.
This allows issuers to forward the required infrastructure documentation to their authorities on request, with a full audit trail.
Incident management
Security incidents are visible and managed on the Trusset status page, covering the following services:
Secret management
Development and Staging secrets are managed via Doppler. Production secrets are managed via HashiCorp Vault, deployed in a hardened Docker container.
Contract updates
Trusset cannot update global contracts (e.g. the Identity Register) as a single party. Global contract updates require multisignature approval from the TrussetDAO, consisting of all dedicated issuers in the Trusset ecosystem, and the Trusset Board.
Audit policy
Once a year, Trusset renews all security audits with a chosen third-party auditor based in the EU.
ISO certification with TÜV is in progress and not yet complete. Once it is granted, it enters the same annual renewal cycle.
App updates
You can find the production app changelogs here. Updates undergo a strict, 3-step process that is defined internally and in the Trusset compliance documentation.