How Truesant protects your data and our responsible disclosure programme.
Last updated: June 2026
Truesant handles sensitive employment and payroll data on behalf of thousands of workers and organisations. We treat security as a fundamental responsibility, not a feature. This page describes our security programme, control environment, and how to report vulnerabilities.
Our security programme is aligned with:
For GDPR-specific information, see our GDPR page.
We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a security incident affecting personal data, we follow our breach notification obligations under GDPR — notifying the relevant supervisory authority within 72 hours and affected individuals without undue delay where required.
We take all security reports seriously. If you believe you have discovered a vulnerability in the Truesant platform, please report it responsibly:
Email: security@truesant.com
PGP: Key available on request.
Please include: A clear description of the vulnerability, steps to reproduce, potential impact, and your contact details.
We ask that you:
We will acknowledge your report within 2 business days and aim to resolve confirmed vulnerabilities within 30 days. We do not pursue legal action against researchers acting in good faith under this policy.
Security enquiries: security@truesant.com. For general questions, use our contact page.