Security

Security is fundamental to everything we build at truenumb. Our customers trust us with their most sensitive business data, and we take that responsibility seriously.

Encryption in transit

All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). We do not support unencrypted connections.

Encryption at rest

All data stored on our servers is encrypted at rest using industry-standard AES-256 encryption via Microsoft Azure.

Cloud infrastructure

truenumb runs on Microsoft Azure, one of the world's most trusted cloud platforms, with enterprise-grade physical and network security.

Authentication

We use JSON Web Tokens (JWT) for session authentication. Passwords are stored as bcrypt hashes — we never store plain text passwords.

Role-based access control

Every dataset has granular permission settings. Users only see and access the data they are explicitly authorised to view or edit.

Audit trail

Every data entry, review, approval and lock action is logged with a timestamp and the user who performed it. Nothing can be changed without a record.

Payment security

Card payments are handled entirely by Stripe, which is PCI DSS Level 1 certified. We never store or process card details on our servers.

Data isolation

Each company's data is logically isolated. Users can only access data belonging to their own company or companies they have been explicitly invited to.

Reporting a vulnerability

If you discover a security vulnerability in the truenumb platform, please report it responsibly to us at hello@truenumb.com. We will investigate all reports promptly and work to address verified issues as quickly as possible.

Questions

If you have any questions about our security practices, please contact us at hello@truenumb.com.