TroutTrout
Trout Software Trust Center

Security & trust

We build security for critical infrastructure, and we run our own program the same way. Trout is on-premise by design, so we hold none of your operational data, and our controls are aligned with ISO 27001, SOC 2, and CMMC Level 1.

Request access28 controls across 6 domains. Updated July 2026.
SOC 2
Trust Services Criteria
Aligned
ISO/IEC 27001
Annex A controls
Aligned
CMMC Level 1
Foundational (FCI)
Aligned
On-premise by design
No customer data in our cloud
Architecture

“Aligned” means our program is built to the framework's control objectives. Current attestation status and evidence are shared under NDA on request.

The core of our posture

We do not hold your data

Most security vendors ask you to send your data to their cloud. Trout does the opposite. Access Gate is deployed on-premise, on hardware you own, so your operational data never leaves your facility. There is no Trout-operated cloud holding your OT data, which removes an entire class of risk before any control is applied. We are a French company governed by French law, outside the reach of the US Cloud Act and FISA 702, and our source code is auditable by qualified customers under NDA.

Controls

28 controls, mapped to our frameworks

The controls our program maintains, grouped by domain. Expand a domain to see the individual controls. The framework mapping and supporting evidence are available under NDA on request.

Data protection & privacy5 controls
  • Customer operational data, logs, and telemetry stay on-premise and never reach a Trout-operated cloud
  • Data encrypted in transit and at rest
  • Data governed by French law, outside the US Cloud Act and FISA 702
  • Documented data retention and deletion policy
  • Published privacy policy covering website and business data
Access control4 controls
  • Least-privilege access to internal systems
  • Multi-factor authentication required for system access
  • Role-based permissions with unique, non-shared accounts
  • Periodic access reviews and prompt revocation on offboarding
Infrastructure & network security5 controls
  • Segmentation of internal networks
  • Endpoint protection on company devices
  • Encrypted channels for administrative access
  • Security-relevant events logged and retained
  • Backups with tested recovery procedures
Product security5 controls
  • Secure SDLC with mandatory code review on every change
  • Automated dependency-vulnerability scanning gating each release
  • Releases blocked on un-reviewed moderate-or-higher vulnerabilities
  • Source code auditable by qualified customers under NDA
  • Tamper-evident audit trails produced in customer environments
Organizational security5 controls
  • Documented, periodically reviewed security policies
  • Recurring security-awareness training for staff
  • Confidentiality agreements for personnel and contractors
  • Background verification where permitted
  • Risk-assessment process feeding remediation
Incident response & resilience4 controls
  • Documented incident-response process with defined roles and severity triage
  • Customer-notification commitments for incidents that affect them
  • Coordinated vulnerability disclosure program
  • Business-continuity and recovery procedures sized for critical-infrastructure operators
Documents & resources

Available under NDA on request

Buyers, auditors, and prime contractors can request the documentation below. Tell us what your assessment needs and we will share it under NDA.

Security overview & control mapping
How our controls map to ISO 27001, SOC 2, and CMMC L1
Request
Attestation status
Current SOC 2 / ISO 27001 posture and roadmap
Request
Penetration test summary
Latest third-party assessment, executive summary
Request
Subprocessor list
Current subprocessors and their purpose
Request
Source-code audit (NDA)
Supervised review for qualified defense / OIV customers
Request
Report a vulnerability

Coordinated disclosure

If you believe you have found a security vulnerability in a Trout product or in this website, tell us. We practice coordinated disclosure: we acknowledge your report, work with you on a fix and a timeline, and credit you if you would like. Please give us a reasonable window to remediate before any public disclosure.

Questions about our security?

Send us your security questionnaire, your assessment requirements, or a request for any document above. We answer quickly, and honestly.