Catalogue and visitor accounts
Anyone may browse the participating-company catalogue and current public control matrix. A free visitor account is required to read detailed TrustData conclusions, history, and recommendations. We process the visitor’s name, email address, authentication records, and essential security metadata for account access; marketing consent is separate and optional.
Founder accounts
We process account identity, organization membership, billing status, scope declarations, evidence, findings, verification state, and publication state to provide the service and protect tenant boundaries. Founder declarations are stored separately and never treated as badge evidence.
Repository and provider evidence
TrustData is designed to collect configuration metadata and redacted evidence rather than customer content. Temporary repository workspaces are deleted after scanning.
- No persistent GitHub installation tokens
- No environment variable values
- No complete repository retention
- No training on submitted customer code
Retention and deletion
Evidence retention is kept short and tied to assessment needs. Visitors and organization administrators may request account export or deletion, subject to security, audit, and legal retention obligations.
Contact
Privacy questions and rights requests may be sent to privacy@trustdata.example. Production deployments must replace this example address with the configured TrustData privacy contact.