Trust

The controls, the evidence behind each one, and TollRelay's sub-processors.

TollRelay is not certified. Certification is the audit scheduled at incorporation, and until it completes the honest claim is the one above: these controls are implemented as marked, here is the evidence, and no third party has yet reviewed it.

Controls

Reviewed 15 September 2026 against the scaffold on develop.

Security controls, their status, their implementation and their evidence
ControlStatusImplementationEvidence
Tenant isolationBuiltForced row-level security on every table that carries organisation_id, in both planes and on the control plane's receipts. One sanctioned access path. The Workers connect as a login role that is a member of the application role.The row-level security proof in packages/db/test, run in CI; the deploy's login-role privilege check.
Regional residencyPartialEvery organisation carries a region, encoded in every identifier. Five databases across Frankfurt and Virginia. The residency test reads the region map. The cross-region alarm is planned.infra/neon/provision.test.ts; the region column and the id prefixes.
No money heldBuiltNo code path takes a payment, holds a balance, settles to a seller or enforces a mandate on its own. The verify route refuses a voucher, a word that names nothing in v3.1. Amounts are integers in the database and decimal strings on the wire.apps/api/test/app.test.ts; the contract's money tests.
Signing keysPartialPer-plane signer Worker, keys in the Secrets Store bound read-only, public halves only at the JWKS, two entrypoints so the directory caller cannot sign. Provisioning waits on the founder.The key inventory below, once keys exist; the revocation drill, once written.
Machine key custodyBuiltA machine's private key is returned once at creation and never stored; only the public half is in the plane.The plane schema and the no-personal-data catalogue test, which refuses a private column.
Change controlBuiltEvery change to an organisation, an identity, a mandate or a key writes an append-only receipt row.The append-only proof in CI.
Fail-closed credentialsBuiltA missing or malformed credential answers 401 with the challenge; a write without an Idempotency-Key answers 400; a missing secret throws before any handler runs.apps/api/test, apps/auth-region/test.
Personal data in errorsBuiltValidation errors name fields, never values. No email, name, wallet or key material in a body or a log line.apps/api/test asserts the value is absent.
Transport and headersBuiltCustom domains with the edge provider's certificates, HSTS with preload, nosniff, frame denial, a hash-listed content security policy on the site and a strict one on the dashboard.packages/config/security-headers.mjs, apps/web/src/lib/csp.test.ts.
SecretsBuiltNo secret in code, CI or an environment file. gitleaks blocks the pull request. One CI identity by OIDC; Workers read bindings only.The secret scan results from every run.
Access controlPlannedRoles owner, admin, finance, support with expiring memberships are in the schema. The step-up before revoking a key and the access review export are planned.The access review export, once it exists.
Incident and availabilityPlannedThe incident runbook commits to notice within twenty four hours. The status page is a placeholder.docs/runbooks/incident.md; the status history once the page exists.
BackupsPlannedThe provider's daily snapshots and a nightly encrypted export, once the projects exist.docs/runbooks/backups.md; the restore drill log.
Sub-processorsBuiltSeven named suppliers, listed with what each receives.docs/security/sub-processors.md.
AccessibilityBuiltWCAG 2.2 AA by construction: the contrast gate over every token pair in both themes and axe over every route in both themes.bun run gate:contrast, bun run gate:axe, in CI.

Key inventory

No signing key exists yet. The table fills when the founder provisions the Secrets Store.

Signing key inventory
KeyPlaneRegionPurposeGeneratedRotation
None yet.

SOC 2 and ISO 27001 mapping

The controls above map to trust services criteria and Annex A controls as follows. The auditor confirms the mapping; it is stated so the build has something to prove.

Control mapping to SOC 2 and ISO 27001 Annex A
ControlSOC 2ISO 27001:2022 Annex A
Tenant isolationCC6.1, CC6.3A.5.15, A.8.3
Regional residencyCC6.1, P4.1A.5.31, A.8.10
No money heldCC2.2A.5.34
Signing keysCC6.1, CC6.7A.8.24
Machine key custodyCC6.1, CC6.7A.8.24
Change controlCC8.1A.8.32
Fail-closed credentialsCC6.1, CC6.6A.8.5
Personal data in errorsCC7.2, P6.1A.8.15
Transport and headersCC6.7A.8.20, A.8.24
SecretsCC6.1A.8.24
Access controlCC6.2, CC6.3A.5.16, A.5.18
Incident and availabilityCC7.3, CC7.4, A1.2A.5.24, A.5.26, A.5.30
BackupsA1.2A.8.13
Sub-processorsCC9.2A.5.19, A.5.21

Sub-processors

Seven suppliers will process data on TollRelay's behalf. Each row says what that supplier sees. Anything not on this list does not receive customer data. Certifications belong to the supplier and are published on the supplier's own trust page.

Written 15 September 2026 against the scaffold. Reviewed quarterly; any addition or removal is a change to this file, to the trust page and to the customer notice in the same pull request.

Sub-processors, what each sees, its region and its next review
Sub-processorWhat it seesRegionNext review
CloudflareEvery request to every surface: address, headers, path, and the bytes served. Runs every Worker and holds the signing keys in its Secrets Store bound to the signer.Global network. Data, keys and logs are pinned to region.15 December 2026
NeonAll stored data. The control plane holds registries and keyed hashes. The identity databases hold people. The planes hold organisations, machines, mandates, spend, receipts.Control and European databases in Frankfurt. United States in Virginia.15 December 2026
InfisicalSecrets only. It never sees customer data.European cloud.15 December 2026
DiditThe business verification: the organisation's legal identity, its beneficial owners and the sanctions screen. TollRelay stores the result as a state, never the documents.Per their trust page.15 December 2026
StripeSubscription and invoice data for a paying organisation or verifier: the buyer's name, email, billing address and card, which TollRelay never holds itself.United Kingdom entity, processing globally.15 December 2026
ResendOutbound email: the recipient address, the subject and the body of every sign-in message, and the delivery result.European region on the sending domain.15 December 2026
A sanctions list providerThe keyed hash of a wallet or a legal name screened at first sight. Chosen with the sanctions issue; named here when it is.To be recorded.15 December 2026

What none of them see

The private half of a machine key: it is returned once to the organisation and never stored anywhere. The private half of a TollRelay signing key: held by one supplier, the edge provider, in its Secrets Store, bound read-only to the signer.

Retention

Data retention, its bound and how it is enforced
RowBoundEnforced
An idempotency keyTwenty four hours after the writeThe column is set on every row; the maintenance role prunes.
An invitationSeven days, or acceptanceDeleted on acceptance; expired rows pruned.
A verification codeTen minutesbetter-auth's own expiry.
A spend rowAs long as the organisationAppend-only; exported on request; deleted with the organisation.
A KYB checkAs long as the organisationA state and a session reference, never a document.