Skip to content

Vendor due diligence

Public security & procurement overview

Verified information for security, legal and procurement teams: EU data residency, sub-processors, core application controls, continuity and contracting routes. Need a formal questionnaire completed (SIG, CAIQ or your own template)? Email hello@trusq.io.

This public overview does not claim a certification or independent assurance report. Product-specific requirements and contractual commitments are handled in the applicable due-diligence and agreement process.

Company & contract

In placeWho is the legal entity behind Trusq?
Trusq is a product of YRproject B.V., registered in the Netherlands (EU), KvK 97813974, at IJsseldijk 402, 2922 BN Krimpen aan den IJssel.
At onboardingIs there a Data Processing Agreement?
Yes. A GDPR Art. 28 DPA (your organisation as controller, Trusq as processor) is provided for signature during onboarding, before any production use. See the trust page.
In placeWhat are the terms of service and governing law?
Our terms apply, governed by Dutch law. Trusq provides information and indications, not legal advice.

Data protection & residency

EU onlyWhere is our data hosted and processed?
Entirely within the European Union. Application and database hosting is in Germany and France; every sub-processor is EU-based. No data is hosted or processed in the US.
EU onlyWhere is AI processing performed?
Content you submit for drafting or the assistant is processed by our EU AI provider (Mistral AI, France) — never by US AI services. See sub-processors.
YesIs our content used to train AI models?
No. Content you submit is used to provide the service to you, grounded in cited sources; it is not used to train models.
In placeWho are your sub-processors?
Three, all EU-based: Hetzner (DE) for hosting, Mistral AI (FR) for the AI layer, INWX (DE) for transactional email. Full detail and purpose on the sub-processors page.
In placeWhat personal data do you process, and for how long?
Account data, the compliance data you enter, commercial enquiries and server/audit logs. Retention is set out in our privacy policy (e.g. server and audit logs for 90 days).
At onboardingHow is data returned or deleted at the end of the contract?
On termination we return or delete your data in line with the DPA and privacy policy. The applicable process and timing are recorded during onboarding.

Security controls

In placeIs data encrypted in transit?
Yes. All traffic is served over HTTPS/TLS, with HTTP Strict Transport Security (HSTS) and a Content-Security-Policy enforced at the edge (default-src 'self', object-src 'none', framing restricted; inline scripts/styles remain permitted pending a hash migration).
In placeHow are passwords stored?
Passwords are hashed with salted PBKDF2-HMAC-SHA256 (200,000 iterations, per-user salt). We never store plaintext passwords. Sessions use a signed, HttpOnly cookie.
In placeHow is customer data separated between tenants?
Trusq is multi-tenant; each organisation’s data is separated per tenant in the application and database. Implementation detail is available during onboarding.
In placeDo you enforce security headers?
Yes — HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a Content-Security-Policy are set on the public surface.

Resilience & continuity

In placeDo you take backups?
Yes. The database is backed up automatically each day, with an independent off-site copy kept on separate infrastructure. Restore evidence and the operational view are available during due diligence.
In placeWhere can reviewers inspect current service evidence?
Current operational and continuity evidence is available on the status page. Any contractual service commitment is stated in the applicable agreement.
In placeDo you have a documented incident-response process?
For personal-data breaches we notify the controller without undue delay, as required under the GDPR and set out in the DPA. Security concerns can be reported through our responsible-disclosure route.
← Back to trust & data