Security

What Truing stores, who processes it, and how to report a vulnerability.

Accounts

Truing has no user accounts, no sessions and no sign in. The free check needs none, and a paid engagement is run over email against files you send directly.

What it holds

There is no database in this product, and no payroll register is ever uploaded to this site. The engagement itself is run against files you send directly.

Payment pages are Stripe's own hosted checkout on a Stripe domain, so a card number is never typed on this site.

Who processes it

Reporting a vulnerability

The contact, the policy and the expiry are published at /.well-known/security.txt, per RFC 9116. That file is generated from this product's own declaration by ops/security-txt.mjs, so the address here and the address a researcher's tooling reads are one string.