01Where your data lives
The platform is deployed into a cloud tenant that you own and pay for. The database, the pipeline and the reports all sit inside that subscription. We operate it for you, and the environment itself is yours.
There is no shared database holding several clients' figures side by side. Your numbers are not pooled with anyone else's, and no other client is ever one configuration mistake away from seeing them.
Cloud infrastructure is provided by a major provider operating under a current SOC 2 report. TRU47 Intel's own SOC 2 program is underway, and we will say so plainly here when it is complete rather than before.
02Who can reach it, and how that is recorded
Access to your environment is limited to the named people on your engagement team. Every one of them signs in with multi factor authentication, and the cloud platform's own activity log records who signed in, when, and what they touched. That log lives in your tenant, so you can read it without asking us for it.
We will name the individuals with access at the start of the engagement and tell you when that list changes. If you want an access review at any point, ask and we will run it with you.
03How credentials are handled
- Read only, always. Every connection uses the narrowest role the source system offers. The platform cannot place an order, issue a refund, move money, or post a journal entry.
- Issued in your environment. Credentials are created by your team in your accounts, so you can see what was granted and revoke it without our help.
- Stored in the platform's key vault, never in code, never in a spreadsheet, and never sent over email or chat.
- Rotated on a schedule, and immediately on any personnel change on either side.
Because the platform never writes to your books, it cannot introduce an error into your financial records. It sits outside your financial reporting controls rather than inside them. If you are audited, or preparing for a sale or a raise, that distinction is the one your accountant will care about.
04Subprocessors
The systems we connect to are the ones you already use, and you decide which. Typically that is your accounting system, your bank, your billing or point of sale, your payroll provider and your CRM. Beyond your own cloud provider, we keep the list of third parties involved in operating the platform short on purpose.
A current list of subprocessors is provided before anything connects to live data, and we will tell you in advance if it changes.
05What happens when it ends
The environment is yours, so nothing has to be handed back. If we part ways, we remove our access, transfer administrative control to whoever you name, and the platform keeps running with everything in it.
The reconciliation logic is plain SQL your own team or another firm can read. There is no proprietary black box that stops working when we leave.
If you would rather the whole thing be removed, say so and we will decommission it and confirm in writing when it is done.
06If something goes wrong
If we become aware of a security incident affecting your data or your environment, we will notify your named contact without undue delay, and in any case within 72 hours of confirming it. The notice will say what we know, what we do not yet know, and what we are doing about it.
We would rather tell you early with an incomplete picture than tell you late with a tidy one.
Send them over before the first call rather than after. We will answer in writing, and if the honest answer is that something is not built yet, that is what you will get. Reach us at hello@tru47intel.com.