Security
What Truing stores, who processes it, and how to report a vulnerability.
Accounts
Truing has no user accounts, no sessions and no sign in. The free check needs none, and a paid engagement is run over email against files you send directly.
What it holds
- The register you give the free readiness check is read to answer it and is not stored
- If you buy, the payroll register you upload on your order page, and the files built from it, are stored for 12 months after delivery and then deleted
- If you buy, Stripe collects your billing address and your card
- Anonymous usage analytics: page views and clicks. Form inputs are masked in session recordings and no profile is created for a visitor who never identifies themselves
The free check stores nothing. A paid order's register is uploaded on that order's own page, stored in a private bucket, and read only by the order runner.
No AI model computes any figure. No employee name, SSN, address, date of birth, bank detail or pay figure is sent to a model provider. A CSV with standard column names never reaches one.
Payment pages are Stripe's own hosted checkout on a Stripe domain, so a card number is never typed on this site.
Who processes it
- Stripe, takes the payment and holds the card details. We never see a card number.
- PostHog, anonymous product analytics, proxied through this domain.
- Cloudflare, serves this site and holds its access logs.
- Supabase, stores paid-order uploads and the finished files.
- Google Gemini API, matches unusual column names from the header row alone, and unusual job titles from the title alone. It is never sent an employee name, id or pay figure.
- Resend, sends the order link and the delivery email.
Reporting a vulnerability
The contact, the policy and the expiry are published at /.well-known/security.txt, per RFC 9116. That file is generated from this product's own declaration by ops/security-txt.mjs, so the address here and the address a researcher's tooling reads are one string.