Security & trust
We build security for critical infrastructure, and we run our own program the same way. Trout is on-premise by design, so we hold none of your operational data, and our controls are aligned with ISO 27001, SOC 2, and CMMC Level 1.
“Aligned” means our program is built to the framework's control objectives. Current attestation status and evidence are shared under NDA on request.
We do not hold your data
Most security vendors ask you to send your data to their cloud. Trout does the opposite. Access Gate is deployed on-premise, on hardware you own, so your operational data never leaves your facility. There is no Trout-operated cloud holding your OT data, which removes an entire class of risk before any control is applied. We are a French company governed by French law, outside the reach of the US Cloud Act and FISA 702, and our source code is auditable by qualified customers under NDA.
28 controls, mapped to our frameworks
The controls our program maintains, grouped by domain. Expand a domain to see the individual controls. The framework mapping and supporting evidence are available under NDA on request.
Data protection & privacy5 controls
- Customer operational data, logs, and telemetry stay on-premise and never reach a Trout-operated cloud
- Data encrypted in transit and at rest
- Data governed by French law, outside the US Cloud Act and FISA 702
- Documented data retention and deletion policy
- Published privacy policy covering website and business data
Access control4 controls
- Least-privilege access to internal systems
- Multi-factor authentication required for system access
- Role-based permissions with unique, non-shared accounts
- Periodic access reviews and prompt revocation on offboarding
Infrastructure & network security5 controls
- Segmentation of internal networks
- Endpoint protection on company devices
- Encrypted channels for administrative access
- Security-relevant events logged and retained
- Backups with tested recovery procedures
Product security5 controls
- Secure SDLC with mandatory code review on every change
- Automated dependency-vulnerability scanning gating each release
- Releases blocked on un-reviewed moderate-or-higher vulnerabilities
- Source code auditable by qualified customers under NDA
- Tamper-evident audit trails produced in customer environments
Organizational security5 controls
- Documented, periodically reviewed security policies
- Recurring security-awareness training for staff
- Confidentiality agreements for personnel and contractors
- Background verification where permitted
- Risk-assessment process feeding remediation
Incident response & resilience4 controls
- Documented incident-response process with defined roles and severity triage
- Customer-notification commitments for incidents that affect them
- Coordinated vulnerability disclosure program
- Business-continuity and recovery procedures sized for critical-infrastructure operators
Available under NDA on request
Buyers, auditors, and prime contractors can request the documentation below. Tell us what your assessment needs and we will share it under NDA.
Coordinated disclosure
If you believe you have found a security vulnerability in a Trout product or in this website, tell us. We practice coordinated disclosure: we acknowledge your report, work with you on a fix and a timeline, and credit you if you would like. Please give us a reasonable window to remediate before any public disclosure.
Questions about our security?
Send us your security questionnaire, your assessment requirements, or a request for any document above. We answer quickly, and honestly.