Security

What Truing stores, who processes it, and how to report a vulnerability.

Accounts

Truing has no user accounts, no sessions and no sign in. The free check needs none, and a paid engagement is run over email against files you send directly.

What it holds

The free check stores nothing. A paid order's register is uploaded on that order's own page, stored in a private bucket, and read only by the order runner.

No AI model computes any figure. No employee name, SSN, address, date of birth, bank detail or pay figure is sent to a model provider. A CSV with standard column names never reaches one.

Payment pages are Stripe's own hosted checkout on a Stripe domain, so a card number is never typed on this site.

Who processes it

Reporting a vulnerability

The contact, the policy and the expiry are published at /.well-known/security.txt, per RFC 9116. That file is generated from this product's own declaration by ops/security-txt.mjs, so the address here and the address a researcher's tooling reads are one string.