Legal

Security

Last updated: 22 September 2026

This page describes the security practices and trust boundaries of Trigora Cloud. It is not a certification and does not mean Trigora operates as a zero-knowledge service.

Encryption

Persisted customer artifacts and execution data are encrypted at rest through the underlying infrastructure.

Data in transit is protected using TLS.

Workload isolation

Customer workloads execute in isolated runtime environments designed to prevent one customer from accessing another customer’s code or execution state.

Access controls

Access to production systems and customer data is restricted to authorized personnel and systems according to operational need.

Customer artifacts and execution resources are authorized by workspace and project.

Secrets

Trigora is designed to keep secrets separate from Program source.

Do not embed API keys, credentials, tokens, or other secrets directly in Program source, event payloads, or other configuration that you do not want persisted with an Execution.

Operational logs and product analytics are configured to avoid capturing Program source, execution payloads, and secret values except where technically necessary to provide or troubleshoot the service.

Customer ownership

You retain ownership of your Programs and Customer Content.

Trigora does not acquire ownership of your Program source code, deployed artifacts, execution data, or other Customer Content.

The limited license you grant Trigora to process Customer Content exists only so we can operate and provide the service, as described in our Terms of Service.

AI training

Private Customer Content is not used to train public or third-party AI models.

Trust boundary

Trigora infrastructure necessarily processes your code and execution data in order to run your Programs.

Encryption at rest protects stored data from unauthorized access to the underlying storage media. It does not mean Trigora runs Customer Content in a zero-knowledge environment or is technically unable to process that content.

Account security

Customers are responsible for protecting account credentials, API tokens, secrets, and external-service credentials used with Trigora.

Credentials that may have been exposed should be revoked or rotated promptly.

Security incidents

If Trigora becomes aware of a security incident affecting Customer Content, we will investigate and notify affected customers as required by applicable law and applicable contractual commitments.

Retention and service providers

Our data-retention practices are described on the Data processing page.

Current subprocessors and service providers are named on the Subprocessors page.

Responsible disclosure

Security issues can be reported to [email protected].

Please include enough detail for us to understand and reproduce the issue where possible, and give us a reasonable opportunity to investigate and remediate it before public disclosure.