TPSaaS Trust Center

Trust Center

Security assurance you can verify.

TPSaaS combines established security controls, recognized framework alignment, accountable human governance and independently measured external security posture.

Assurance requests are reviewed by our Operations team before any controlled or confidential evidence is disclosed.

Public proof

Security assurance at a glance

Public signals distinguish evidenced baselines, framework alignment, independent external measurement and work in progress.

Verified baseline

MVSP

TPSaaS uses the Minimum Viable Secure Product requirements as its evidenced security baseline.

View MVSP baseline
Aligned

ISO/IEC 27001

Security governance and control practices are aligned to ISO/IEC 27001.

Aligned

SOC 2 Type 2

Control design and operating practices are aligned to relevant Trust Services Criteria.

Externally measured

BitSight rating: 750

BitSight observation on September 3, 2026: 750, Advanced band, and better than similar companies.

View the measurement boundary
WIP · Controlled · Confidential

Penetration testing

Independent penetration testing is in progress. Reports and sensitive testing artifacts are not public.

Framework alignment describes the security practices and control expectations used to design and operate TPSaaS. It does not represent third-party certification or attestation unless explicitly stated.

Security controls

How TPSaaS secures the platform

Six control domains work together to protect access, information, product change, infrastructure and accountable response.

01

Identity and access

Role-based access, controlled authentication and accountable administration help restrict platform access to authorized users and appropriate functions.

02

Data protection

Information is handled according to its purpose, access requirements and applicable protection needs.

03

Secure development

Security review and testing are integrated into the product-change lifecycle to reduce change-related risk.

04

Infrastructure security

TPSaaS maintains responsibility for application configuration and operation while defined providers secure their respective service layers.

05

Vulnerability and incident management

Potential security weaknesses and events are triaged, prioritized and handled through governed response processes.

06

Governance and accountability

Named human owners remain accountable for security decisions, evidence and review.

Independent external observation

Independent external security posture

TPSaaS supplements internal security controls with independent outside-in visibility of its externally observable digital exposure.

BitSight security rating

750 · Advanced

Better than similar companies

Source: TPSaaS company overview in BitSight, observed September 3, 2026: rating 750, Advanced band, and better than similar companies. Ratings can change. This independent outside-in signal is not a certification or endorsement and does not replace internal controls, penetration testing, or human security governance.

Infrastructure

Provider assurance with clear boundaries

TPSaaS uses AWS Europe (Frankfurt) for cloud infrastructure. AWS maintains independent assurance for applicable services and regions.

Primary cloud infrastructure

AWS Europe (Frankfurt)

TPSaaS remains accountable for its application, configuration and operating controls. AWS remains responsible for controls within the applicable cloud service scope.

Provider certifications and attestations apply to the provider and services within their certified scope. They do not constitute certification of TPSaaS.

Service providers

Key service providers

TPSaaS uses established technology providers for defined parts of the service. Public assurance information is linked below where available.

Business operations and customer-service tooling

Zoho

TPSaaS boundary: configuration, authorized use, access governance and information entered into the services.

View Zoho compliance
Identity and productivity services

Google Workspace

TPSaaS boundary: account configuration, access administration, data use and appropriate security settings.

View Google assurance
Payment processing

Stripe

TPSaaS boundary: approved integration, account controls and use of Stripe services within the payment flow.

View Stripe security

Assurance resources

Assurance evidence by disclosure level

Assurance evidence is classified according to disclosure risk. Public evidence is openly available. Controlled and confidential evidence is reviewed before release.

Public

Open assurance

  • MVSP verified baseline
  • ISO/IEC 27001 alignment
  • SOC 2 Type 2 alignment
  • High-level control domains
  • Independent external posture signal
  • Public policies and disclosure routes
Controlled

Reviewed access

  • Architecture and security pack
  • Detailed control mappings
  • Provider assurance reports
  • Security questionnaires
  • Hosting and subprocessor evidence
Confidential

Restricted evidence

  • Penetration testing in progress; reports remain controlled and confidential
  • Sensitive architecture detail
  • Vulnerability and testing artifacts
  • Internal policies and control evidence
  • Proprietary operating methods and IP
Controlled disclosure

Request Assurance Access

For due diligence, questionnaires and controlled evidence.

Request Assurance Access

Protected routes

Need something specific?

Use the protected route that matches your request.

FAQ

Assurance questions, answered clearly

What security standards and frameworks does TPSaaS align to?

TPSaaS uses MVSP as its evidenced security baseline. Our security governance and control practices are aligned to ISO/IEC 27001, and our control design and operating practices are aligned to relevant SOC 2 Type 2 Trust Services Criteria. Framework alignment does not itself represent third-party certification or attestation.

How does TPSaaS protect customer information?

TPSaaS applies security practices across identity and access, data protection, secure development, infrastructure security, vulnerability and incident management, and governance. Controls are designed around authorized access, accountable administration and proportionate protection of information.

Where is the TPSaaS platform hosted?

TPSaaS uses AWS Europe (Frankfurt) for its primary cloud infrastructure. TPSaaS remains accountable for its application, configuration and operating controls, while AWS is responsible for controls within the applicable AWS service scope.

How does TPSaaS assure its own service providers?

TPSaaS applies third-party assurance principles to its own provider ecosystem. Material providers currently surfaced in the Trust Center include AWS, Zoho, Google Workspace and Stripe, with public links to their relevant security and compliance resources and clear responsibility boundaries.

What assurance information is publicly available?

Public assurance includes our MVSP evidenced baseline, ISO/IEC 27001 and SOC 2 Type 2 alignment, high-level security practices, official provider-assurance links and a BitSight external posture signal. More detailed evidence may be classified as Controlled or Confidential.

What evidence requires controlled access?

Detailed architecture and security packs, control mappings, provider reports, security questionnaires and certain hosting or subprocessor evidence may require review before disclosure. Sensitive materials such as penetration-test reports, vulnerability artifacts and internal control evidence are treated as Confidential.

How can I request additional assurance information?

Customers, prospects and authorized assessors can use Request Assurance Access. Operations reviews each request before any controlled or confidential material is released, and submission does not guarantee disclosure.