Trust & Security

Built for teams that can't compromise on security

TrigCode is how enterprises ship AI-built software — so the platform is built to enterprise expectations: encrypted by default, auditable end to end, and integrated with the identity stack you already run.

Encryption

All traffic is served over TLS. Secrets held on your behalf — SSO client secrets, webhook signing secrets, 2FA seeds — are encrypted at rest with AES-256-GCM. API keys and SCIM tokens are stored only as SHA-256 hashes.

SSO & SCIM

Enterprise workspaces bring their own identity provider over OIDC (Okta, Microsoft Entra ID, and others), with domain-claim approval to prevent takeover. SCIM 2.0 provisioning creates and removes members automatically as people join and leave your company.

Role-based access

Fixed four-role matrix (owner, admin, developer, viewer) enforced server-side on every request. Org context is validated per-request and never embedded in session tokens. Per-member monthly credit caps limit blast radius.

Audit logs

Every privileged action in a workspace — invites, role changes, key issuance, deploys, SCIM provisioning — lands in a member-visible audit trail with actor snapshots that survive account deletion. Admins can export the full trail as CSV.

Infrastructure

TrigCode runs on AWS (Mumbai, ap-south-1) with an isolated PostgreSQL database (RDS), automated daily backups, and least-privilege IAM. Generated apps execute in sandboxed previews isolated from the platform.

Your cloud, your data

Enterprise deploys push to YOUR AWS account via a cross-account role you control, scoped to named resources and guarded by an external ID. Code exports include Docker and Terraform so you are never locked in.

Compliance

Our SOC 2 Type I audit is in progress, with Type II to follow. Control mapping and evidence collection are underway across access control, change management, availability, and vendor management. Enterprise customers can request our security whitepaper and current control status under NDA.

SOC 2 Type I — in progressSOC 2 Type II — plannedDPA available

Common questions

Where is my data stored?

In AWS ap-south-1 (Mumbai, India). Payment card data never touches our servers — it is handled entirely by our payment processors: Razorpay in India and Paddle (Merchant of Record) internationally.

Do you train AI models on my code?

No. Prompts are processed by our model providers under their enterprise terms; we do not sell your prompts or generated code, and private apps are visible only to you and your workspace.

How do I report a vulnerability?

Email security@trigcode.com. We acknowledge reports within 48 hours and keep you informed through remediation.

Can we get a DPA?

Yes — enterprise agreements include a data processing addendum. Contact your account manager or sales@trigcode.com.

Security contact

Found something? Email security@trigcode.com. We respond to every report within 48 hours.