Trust Center · TreyTech

Trust you can verify.

How we secure your work, protect your data, and prove it. Our controls, our compliance roadmap, and the reports we share with clients and partners - all in one place.

Last reviewed: September 2026 · Updated quarterly

01 · Compliance

SOC 2 program status.

TreyTech is aligning its platform and operations to the AICPA Trust Services Criteria. Our SOC 2 program covers the TreyTech app, client portal, TreyTech Pros, and the CloudKit®-backed data layer behind them. Reports are issued by an independent CPA firm and shared under NDA.

Two layers beneath us are already attested. Website hosting inherits Netlify's SOC 2 Type 2, ISO 27001, and PCI DSS attestations, available through the Netlify Trust Center. The data layer runs on Apple's platform security. TreyTech's own SOC 2 covers what those reports cannot: our people, our policies, and our controls.

ReportScopeStatus
SOC 2 Type ISecurity, Confidentiality - design of controls at a point in timeIn progress · fast-tracked, target EOY
SOC 2 Type IISecurity, Availability, Confidentiality - operating effectiveness over a 6-month periodObservation window opens immediately after Type I issuance
Penetration testAnnual third-party test of the app, portal, and API surfaceAnnual · summary letter on request
Apple platform reviewApp Store® review for iOS, iPadOS®, macOS®, and tvOS® appsCurrent
Security

Controls are designed and documented.

Access control, change management, vendor management, and incident response policies are written, owned, and reviewed annually.

Availability

Continuity is a commitment.

Recovery objectives are published in our Business Continuity plan and tested against real scenarios.

Confidentiality

Client IP stays client IP.

Confidential materials are limited to the people delivering the work and governed by your signed agreement.

Privacy

We collect what the engagement needs.

Nothing is pooled, profiled, or sold. Details in our Privacy Policy.

02 · Security Controls

How your work is protected.

The platform runs on Apple CloudKit with every record scoped to your Apple® identity. There is no shared password store, no office server, and no single machine that holds your project.

AreaControlEvidence
IdentitySign in with Apple on every surface; roster-gated roles for ProsNo passwords stored by TreyTech
EncryptionTLS 1.2+ in transit; encrypted at rest in the private CloudKit containerApple platform security documentation
AccessLeast privilege; clients see their engagement, Pros see assigned projects onlyRecord-level scoping, quarterly access review
ChangeReviewed builds, TestFlight® staging, App Store releaseRelease history
ContractsElectronic signature for binding agreements and SOWsSigned copy and audit trail per agreement
PaymentsApple Pay® for consults; invoiced card, ACH, or bank transfer for SOWs and project billing; TreyTech never sees full card numbersPCI scope held by Apple and our payment processor
IncidentsImmediate client notification; written report within 72 hoursIncident log
03 · Suppliers & Subprocessors

Who touches your data.

We keep the list short. Each provider is reviewed for its own security posture before it handles client data, and this list is updated when anything changes.

ProviderPurposeData
Apple (CloudKit, Sign in with Apple, Apple Pay, APNs)Platform, identity, payments, notificationsAccount, project, and milestone records
E-signature providerContract and SOW signingAgreement documents and signer identity
Calendly + ZoomConsult scheduling and videoName, email, meeting time
NetlifyWebsite hosting and forms · SOC 2 Type 2, ISO 27001, PCI DSS (report via Netlify Trust Center)Contact form submissions
04 · Request & Report

Ask us. We will show you.

Clients, partners, and prospective clients in procurement can request our SOC 2 report, penetration test summary, and completed security questionnaires. Reports are shared under a mutual NDA within five business days. Everything below goes to one inbox — put the request type in the subject line and it routes from there.

Every request
One inbox, monitored by the team
Reports & questionnaires
Subject: SOC 2 request
SOC 2 reports, security questionnaires, and NDAs
Security disclosure
Subject: Security disclosure
Report a vulnerability - we acknowledge within 24 hours
Privacy requests
Subject: Privacy request
Access, export, or deletion of your data

SOC 2 is a framework defined by the American Institute of Certified Public Accountants. Status shown here reflects the program as of the review date and is not itself an attestation; the report is. Commitments here are in addition to, and do not replace, the terms of your engagement agreement.

S. and other countries and regions.

Start a conversation

Tell us what you are building. We will be in touch.

Paramount Pixel