Security is fundamental to everything we build at truenumb. Our customers trust us with their most sensitive business data, and we take that responsibility seriously.
All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). We do not support unencrypted connections.
All data stored on our servers is encrypted at rest using industry-standard AES-256 encryption via Microsoft Azure.
truenumb runs on Microsoft Azure, one of the world's most trusted cloud platforms, with enterprise-grade physical and network security.
We use JSON Web Tokens (JWT) for session authentication. Passwords are stored as bcrypt hashes — we never store plain text passwords.
Every dataset has granular permission settings. Users only see and access the data they are explicitly authorised to view or edit.
Every data entry, review, approval and lock action is logged with a timestamp and the user who performed it. Nothing can be changed without a record.
Card payments are handled entirely by Stripe, which is PCI DSS Level 1 certified. We never store or process card details on our servers.
Each company's data is logically isolated. Users can only access data belonging to their own company or companies they have been explicitly invited to.
If you discover a security vulnerability in the truenumb platform, please report it responsibly to us at hello@truenumb.com. We will investigate all reports promptly and work to address verified issues as quickly as possible.
If you have any questions about our security practices, please contact us at hello@truenumb.com.