TrueCOI← Back to TrueCOI

Security & trust

Controls that keep evidence defensible.

TrueCOI is built around tenant separation, private evidence, protected human judgment and bounded cloud operations. Security is part of the product model—not a layer added after the workflow.

Tenant-rooted access

Every organization has its own tenant-rooted data and evidence paths. Active membership is the source of tenant role truth, and sensitive commands resolve authorization on the server before accessing records.

Private, immutable evidence

Certificate and import files use tenant-scoped, content-addressed storage. Original evidence is retained, replacement certificates create new versions, and browser deletion of canonical evidence is denied.

Upload protection

Uploads are limited by file type, size and PDF page count. Server-side validation checks file signatures, and a private malware-screening service must return a clean result before evidence is stored.

Review and provenance

Normalized values retain their raw source text, confidence, method, parser version, source document and review attribution. Human-reviewed values cannot be silently replaced by automated extraction.

Auditability

Material commands create append-oriented audit events with actor, tenant, correlation, entity, action, reason and timestamp. Sensitive certificate content is not copied into the audit record.

Bounded cloud operations

TrueCOI applies explicit limits to query size, file size, PDF pages, active certificate volume, job batches, quotas, concurrency and maximum instances. Idempotency markers and deterministic identifiers make retries safe.

Recovery

Firestore point-in-time recovery, scheduled backups, database delete protection, storage soft deletion and portable tenant backup workflows support controlled recovery. Restore procedures are designed around approved tenant-scoped restoration.

Responsible claims

TrueCOI does not claim a compliance certification that has not been independently completed. Security controls and rollout state should be validated during procurement for the specific production environment and customer requirements.

Report a concern

To report a suspected vulnerability or security concern, email security@truecoi.com. Please do not include certificate documents, policy numbers or other sensitive customer data in the initial message.

T
TrueCOI assistantPublic product information
✓

This assistant uses approved public information only. Please do not share certificates or sensitive data.

Hi—ask me a basic question about TrueCOI, certificate workflows, expirations, security or requesting a demo.
Request a demo →