SOC2C

Is this your company? Buyers are checking TrustWorks.io here. Claim trustworks.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
TrustWorks.io logo

TrustWorks.io

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

TrustWorks.io is SOC 2 Type II compliant. TrustWorks.io also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

For digital businesses, taking privacy seriously is now more important than ever. The increasing complexity of data stacks, as well as evolving data protection regulations, require solutions that operationalize and automate privacy programs. That's why we're here. TrustWorks was born in Europe to help businesses reduce privacy operation costs and elevate their privacy posture. You can check the status of all TrustWorks's services on this site https://status.trustworks.io/

Compliance & infrastructure

Hosting
AWSAzure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

12
  • G
    Google Workspace · gsuiteadmin
  • A
    Amazon Web Services · aws
  • A
    Azure DevOps · azuredevops
  • V
    Vanta
  • S
    Slack · slack
  • O
    OpenAI
  • S
    Sentry · sentry
  • N
    Notion · notion
  • M
    Miro
  • H
    Hubspot
  • P
    PostHog · Product analytics, enabling analysis of feature adoption and platform usage, ser
    USA
  • H
    Help Scout · Product guides and onboarding
    USA

Compliance leadership

The person who leads TrustWorks.io's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. TrustWorks.io's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Updates to policiesFeb 2026

Most recent approved policies to be displayed

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is TrustWorks.io SOC 2 compliant?
TrustWorks.io is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is TrustWorks.io ISO 27001 certified?
According to TrustWorks.io's public trust center, TrustWorks.io is ISO 27001 certified. On SOC2C this listing is Listed.
Is TrustWorks.io SOC 2 Type I or Type II?
TrustWorks.io is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use TrustWorks.io's SOC 2 for a vendor risk assessment?
Yes. TrustWorks.io's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is TrustWorks.io penetration tested?
TrustWorks.io hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by TrustWorks.io

Reproduced from TrustWorks.io's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How are TrustWorks APIs secured?
TrustWorks APIs are protected using multiple security mechanisms, including authentication, authorization, and encrypted communication. All API traffic is transmitted over HTTPS, using TLS 1.3, ensuring confidentiality and integrity of data exchanged between clients and the platform.
Is API documentation available for developers and customers?
Yes. TrustWorks provides technical API documentation based on OpenAPI/Swagger specifications, allowing developers to understand available endpoints, request/response formats, authentication requirements, and integration guidelines. API documentation is available at: - https://api.trustworks.io/docs - https://api.trustworks.io/redoc
Is API communication encrypted?
Yes. All API communications are encrypted in transit using HTTPS with TLS 1.2 or TLS 1.3, ensuring secure data transmission between clients, applications, and backend services.
What type, nature, and volume of data is stored, accessed, or processed on your network?
The data belonging to our organization is stored in two locations: AWS RDS and encrypted S3. All of the data is encrypted while at rest, and during communication over the internet, it is encrypted using the HTTPS protocol as well as in transit encryption.
Do you support Single Sign-On (SSO)?
Yes. TrustWorks supports Single Sign-On (SSO) using industry-standard authentication protocols such as SAML 2.0 and OpenID Connect (OIDC). This enables seamless integration with enterprise Identity Providers (IdPs), allowing organizations to centralize identity management and authentication processes. Through this integration, customers can enforce their own identity governance policies, including authentication policies, access lifecycle management, and conditional access rules.