Security
What Truing stores, who processes it, and how to report a vulnerability.
Accounts
Truing has no user accounts, no sessions and no sign in. The free check needs none, and a paid engagement is run over email against files you send directly.
What it holds
- The employee count and the register shape you enter into the readiness check are used to answer it and are not written down here — the check has no database behind it
- If you buy, Stripe collects your billing address and your card
- Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings and no profile is created for a visitor who never identifies themselves
There is no database in this product, and no payroll register is ever uploaded to this site. The engagement itself is run against files you send directly.
Payment pages are Stripe's own hosted checkout on a Stripe domain, so a card number is never typed on this site.
Who processes it
- Stripe, takes the payment and holds the card details — we never see a card number.
- PostHog, anonymous product analytics, proxied through this domain.
- Vercel, serves this site and holds its access logs.
Reporting a vulnerability
The contact, the policy and the expiry are published at /.well-known/security.txt, per RFC 9116. That file is generated from this product's own declaration by ops/security-txt.mjs, so the address here and the address a researcher's tooling reads are one string.