TrustEvidence

Privacy policy

Last updated 4 October 2026. This page describes what the service does today. When the implementation changes, this page changes with it.

Who we are

TrustEvidence is operated by Benjamin Garama Genda, trading as TrustEvidence, the controller of the personal data described here. For any privacy question or request, email support@gettrustevidence.com.

Customers use TrustEvidence to collect evidence from their own systems. For that content we act on the customer's instructions, as their processor. If you are an employee of one of our customers and your data appears in their evidence, please contact your employer first.

What we collect

  • Account details: your name, email address, organisation name and role. Passwords are stored only as scrypt hashes. Two-factor secrets are encrypted.
  • Security records: the IP address and browser user agent of security-relevant actions such as sign-ins, integration changes, exports and approvals, kept in your organisation's audit log. Sign-in attempts are counted against one-way hashes of the email address and IP address to stop password guessing. Policy acknowledgements record the IP address they came from.
  • Customer content: configuration data and evidence collected read-only from the systems your organisation connects (AWS, GitHub, Microsoft Azure and Entra ID, Okta, Google Workspace). This can include the names, email addresses and group memberships of your staff. It also covers documents you upload, findings, reviews and your vendor register. Integration credentials are encrypted and never shown back.
  • Billing: when an organisation subscribes, Stripe processes the payment. We store only Stripe's customer and subscription identifiers, never card numbers.
  • Email: the messages we send (verification codes, password resets, invitations, alerts) are encrypted while queued and their content is deleted once delivered.
  • Server logs: the request path (with secret links redacted), status, timing and a request ID. The web server's access log is turned off.

Cookies and local storage

We set one cookie, te_session, which keeps you signed in for up to 8 hours. It is required for the service to work, sent only over HTTPS and not readable by scripts. Your browser's local storage keeps interface preferences such as the colour theme. There are no analytics, advertising or third-party scripts.

Why we use it

  • To provide the service you signed up for: your account, scans, evidence and reports (performance of a contract).
  • To keep the service and your account secure, and to investigate misuse (legitimate interests).
  • To send the emails the service depends on, such as verification codes, password resets and alerts you choose (performance of a contract).
  • To bill subscriptions and keep the records the law requires (contract and legal obligation).

We do not sell personal data, use it for advertising, or use customer content to train AI models.

Who processes it for us

  • Microsoft Azure: hosting, database and key storage, in the European Union (Spain).
  • Stripe: payments, only for organisations that subscribe.
  • GitHub: sign-in, only if you choose to sign in with GitHub.
  • Our email delivery provider: delivery of the emails listed above.

The systems you connect, and any Slack workspace you send alerts to, are your own providers. We access them only on your instructions. Some of the providers above may process data outside the European Economic Area under their standard data protection terms.

How long we keep it

  • Account and organisation data: while the account exists.
  • Evidence: kept for your plan's retention period after it is collected (Free: 90 days; Team: 400 days; Business: 1100 days) so that it is available for your audits, then deleted. Records on legal hold are kept until the hold is released. To keep the evidence chain verifiable, deletion runs from the oldest record forward, so a record on legal hold also keeps the records collected after it.
  • Integration credentials: deleted immediately when you disconnect the integration or delete the organisation.
  • Sign-in attempt records: deleted after 30 days.
  • Password reset links and invitations: deleted 30 days after they expire, are used or are revoked.
  • IP addresses on policy acknowledgements: erased after 13 months.
  • Audit log: kept for the life of the organisation, because it is part of your audit evidence.

When an owner deletes an organisation, access ends, its integration credentials are destroyed and any paid subscription is cancelled, all immediately. 30 days later everything else is erased permanently, including evidence, documents, the audit log, and the accounts of people who belonged only to that organisation. At the same time we delete its customer record at Stripe, which removes the stored payment details; Stripe keeps the payment history it is required to keep. Encrypted database backups that may still contain the organisation's data expire within 35 days after erasure.

Your rights

You can ask to access, correct, export or delete your personal data, or object to how we use it. Account details can be changed directly in the app, and organisation administrators can export reports and evidence packages. For anything else, contact us; we reply within 30 days. You can also complain to the data protection authority where you live.

Security

How data is encrypted, isolated between organisations and protected against tampering is described on Security, including its known limitations.

Changes

We update this page when what we collect or how we use it changes, and change the date at the top. If a change materially affects you, we email organisation owners before it takes effect.