Rest Assured With Top-Tier Data Security
Trulioo is dedicated to ensuring the highest level of privacy and data security, and it has the credentials to prove it.
Trulioo is committed to data security, risk management and technical support. The Trulioo Information Security and Technical Compliance team delivers layers of preventive measures, including awareness training, to protect Trulioo technology and the data that fuels a global platform of verification services. The team establishes and validates controls and procedures to manage risk while providing the infrastructure to ensure the organization’s continued operations.
Top-Level Credentials Ensure Data Security and Privacy
ISO 27001 Certification
The security framework, created by the International Organization for Standardization (ISO), assesses a company’s ability to keep its data safe through policies, procedures, training, monitoring, auditing, incident response and communications. Trulioo has been ISO 27001-certified since 2015.
SOC 2 Type 2 Qualification
The Service Organization Control (SOC) Type 2, created by the American Institute of Certified Public Accountants, is a cybersecurity framework that establishes standards for how third-party service providers should securely store and process customer data. Truilioo obtained SOC 2 Type 2 in February 2024.
Key Components of the Trulioo Information Security Program
Frequently Asked Questions
Learn more about Trulioo data security and privacy.
Staff members learn the security policy at onboarding, during annual training and in monthly phishing awareness exercises.
Trulioo monitoring tools provide alerts for anomalous access and failed access attempts, which are then manually reviewed as required.
Trulioo has a suite of policies governing information security as required by ISO 27001 and supplemented by business operations. Executive leadership signs off on all policy updates and communicates that to all staff members.
Trulioo requires complex passwords that include at least one special character, one numeral and one upper-case letter. Passwords must be changed at regular intervals.
Service Organization Control Type 2, created by the American Institute of Certified Public Accountants, is a cybersecurity framework that establishes standards for how third-party service providers should securely store and process customer data.
The security framework, created by the International Organization for Standardization, assesses a company’s ability to keep its data safe through policies, procedures, training, monitoring, auditing, incident response and communications.
Trulioo manages access based on the principle of least privilege and on a need-to-know basis.