trōfik
PrivacyTermsAI & DataSecurity & TrustSubprocessors

Security

Security & Trust

A factual overview of how Trofik protects the website and platform, plus our current certification status.

Last updated August 14, 2026

Current compliance status

In progress

Trofik Impact LLC is building its AI management system toward ISO/IEC 42001 readiness and its security-control program toward SOC 2 readiness. Trofik is not currently ISO/IEC 42001 certified and does not currently have a SOC 2 report. We will not represent either milestone as complete unless and until the applicable independent process is completed.

How we approach security

  • Access control: internal features require authentication, project information is scoped to authorized projects, and sensitive administrative functions require elevated access.
  • Database protection: customer and project records use database access controls, including row-level security on relevant public-facing tables.
  • Private file storage: customer uploads are placed in controlled storage paths and delivered through authorized application workflows rather than intentionally public links.
  • Encryption: the production service uses encrypted HTTPS connections. Hosting and storage providers supply encryption protections for stored information under their services.
  • Secrets: provider and administrative credentials are kept in protected deployment configuration and are not intentionally shipped in public browser code.
  • Auditability: the platform records security-relevant and governed actions in audit or activity records where supported by the workflow.
  • Abuse protection: public submissions and AI requests use validation and rate limiting.
  • Development checks: automated tests and security checks cover authentication, authorization, rate limits, environment configuration, and selected high-risk workflows.

Data minimization and retention

We aim to collect only information needed for a defined business or project purpose. Retention controls include a 90-day response-level schedule for public survey responses, project close-out and deletion workflows, and controls intended to keep temporary meeting credentials out of stored session records. Other records follow the applicable customer agreement, operational need, and approved retention process.

AI governance

Our AI-management work includes an AI system inventory, named executive and operational ownership, risk and impact assessment, provider review, output oversight, incident handling, change control, and evidence retention. Eric Chamberlin is the executive sponsor and technical owner. Christian Chamberlin is the AI Management System owner.

See AI & Data for the features and limitations currently represented in the codebase.

Service providers

We use established providers for hosting, database and storage, email, compute, and AI functions. Providers are reviewed according to the information and risk involved. See our current Subprocessor List.

Incident response

We maintain an incident-response process covering identification, containment, investigation, recovery, lessons learned, and required customer or legal notification. If you believe you have found a vulnerability or security incident, please report it promptly and do not access, alter, or download information beyond what is necessary to describe the issue.

Report a security concern

Email christian@trofikimpact.com with a description of the issue, the affected page or feature, and steps to reproduce it. Please do not include unnecessary personal or confidential information.

Customer review

Customers evaluating Trofik may request additional security and privacy information. Availability of confidential materials, testing results, contractual commitments, or audit evidence depends on the engagement and may require a confidentiality agreement.

trōfikTrofik Impact LLC · Brooklyn, NY 11201
PrivacyTermsAI & DataSecurity & TrustSubprocessors