{
  "component-definition": {
    "uuid": "b4a1f6d2-7c3e-4a19-9f5b-2d8e0c6a4713",
    "metadata": {
      "title": "FillTrust security posture",
      "last-modified": "2026-08-30T00:00:00Z",
      "version": "2026-08-30",
      "oscal-version": "1.1.2",
      "remarks": "Self-assessment published by the vendor. This is not an audit, an independent assessment or an authorization. FillTrust holds no SOC 2 report and no ISO 27001 certificate, and states so in the answers below rather than omitting the question.",
      "parties": [
        {
          "uuid": "5e83b027-91cd-4f6b-a84c-3b0d7e21c9f4",
          "type": "organization",
          "name": "FillTrust",
          "email-addresses": [
            "security@filltrust.com"
          ],
          "links": [
            {
              "href": "https://www.filltrust.com",
              "rel": "homepage"
            }
          ]
        }
      ]
    },
    "components": [
      {
        "uuid": "9c2e5f81-3d47-4b6a-8e10-5fa7c93d2be6",
        "type": "service",
        "title": "FillTrust",
        "description": "Software as a service that answers vendor security questionnaires from a customer's own security documentation.",
        "props": [
          {
            "name": "version",
            "value": "2026-08-30"
          },
          {
            "name": "hosting-region",
            "value": "europe-west9 (Paris)",
            "ns": "https://www.filltrust.com/ns"
          }
        ],
        "control-implementations": [
          {
            "uuid": "1f7d4c93-6a25-4e08-b3d9-7c14e850af62",
            "source": "https://raw.githubusercontent.com/usnistgov/oscal-content/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json",
            "description": "Vendor self-assessment against NIST SP 800-53 rev 5, mapped from the answers published at https://www.filltrust.com/trust. Not an independent assessment.",
            "implemented-requirements": [
              {
                "uuid": "b51efd53-07f9-457e-84db-9c51a767eef4",
                "control-id": "sc-8",
                "description": "Is customer data encrypted in transit and at rest? Yes. Everything is encrypted in transit with TLS and at rest by Google Cloud. TOTP secrets are additionally encrypted at the application layer with AES-256-GCM, so a database read alone does not yield a working second factor.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "06e1b78b-c865-4568-929e-7131d08ea3ce",
                "control-id": "sc-28",
                "description": "Is customer data encrypted in transit and at rest? Yes. Everything is encrypted in transit with TLS and at rest by Google Cloud. TOTP secrets are additionally encrypted at the application layer with AES-256-GCM, so a database read alone does not yield a working second factor.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "de319d0c-f114-4821-80cb-f652cf828247",
                "control-id": "ac-3",
                "description": "How is one customer's data kept separate from another's? Every API request derives its tenant from the authenticated session, server-side. No endpoint accepts a customer identifier from the browser, and a request for another tenant's data returns 404 rather than confirming the record exists.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "c11f1037-03f9-4f32-80db-96059b67dc10",
                "control-id": "sc-4",
                "description": "How is one customer's data kept separate from another's? Every API request derives its tenant from the authenticated session, server-side. No endpoint accepts a customer identifier from the browser, and a request for another tenant's data returns 404 rather than confirming the record exists.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "e70402b2-678d-4e77-a146-5edcca72e361",
                "control-id": "sa-9",
                "description": "Where is customer data stored? Documents are stored in Google Cloud in Paris and the database is hosted in Frankfurt, both of them in the EU. Question text and the specific excerpts used to answer are sent to AI providers in the United States under Standard Contractual Clauses. Neither provider trains on API data.\n\nDo you maintain a sub-processor list, and will you sign a DPA? Yes to both. The current sub-processor list and our Data Processing Agreement, including the Standard Contractual Clauses, are published rather than sent on request. You should not have to ask for either.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "8421d6a7-2fb9-44e2-bcdb-f23d6e3dec40",
                "control-id": "ca-2",
                "description": "Do you maintain a current SOC 2 Type II report? No. FillTrust does not hold a SOC 2 report or an ISO 27001 certificate. This page and our security documentation are what we have instead, and we would rather publish that plainly than let the question go unanswered. If certification is a requirement for you, tell us. It is the kind of thing that changes a roadmap.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "not-implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "ef0fabb0-ef62-435f-8bdf-db8a02330f09",
                "control-id": "si-12",
                "description": "Do you delete customer data on request? Yes. Deleting your account cancels billing, removes every uploaded document and generated questionnaire from storage, and deletes your records. If any part of that cannot be completed the deletion is aborted and reported rather than partially applied.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "12c48931-0730-4bc4-8dea-24f32148e28e",
                "control-id": "ia-2",
                "description": "Is multi-factor authentication available? Yes. Accounts are protected by a password with optional TOTP two-factor authentication, and authentication endpoints are rate limited. Enforced SSO is not currently supported.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "cba3a79d-14f3-42f8-b55a-2147b2952962",
                "control-id": "au-2",
                "description": "Can you show who changed an answer, and when? Yes. Every answer change is recorded: what it was, what it became, who changed it and when. That includes answers submitted by outside experts through a review link. Generated answers cite the passages they were drawn from, and a citation that cannot be verified against the source lowers the answer's grade rather than being published.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "caa3a60a-15f3-448b-b45a-1fb4b3952af5",
                "control-id": "au-3",
                "description": "Can you show who changed an answer, and when? Yes. Every answer change is recorded: what it was, what it became, who changed it and when. That includes answers submitted by outside experts through a review link. Generated answers cite the passages they were drawn from, and a citation that cannot be verified against the source lowers the answer's grade rather than being published.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "06b41eb7-4fdd-4f0a-b253-8f29f9160134",
                "control-id": "ra-5",
                "description": "How do you handle reported vulnerabilities? There is a published disclosure policy on our security page and a security.txt at the standard location, both naming a contact that reaches a person. It commits to acknowledging a report within five working days and offers safe harbour for good-faith research within a stated scope. We do not run a paid bug bounty and say so rather than implying one.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "c9817fac-12fe-4409-b5ca-99ba82a4e55f",
                "control-id": "ir-6",
                "description": "What is your incident notification commitment? The commitment in our DPA governs, and it is the document to hold us to. Operationally, uptime is checked continuously, backend errors raise an alert, and object storage is versioned so an accidental overwrite is recoverable.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "f457aee9-8291-4ed8-bdf2-9003ee6482fa",
                "control-id": "si-4",
                "description": "What is your incident notification commitment? The commitment in our DPA governs, and it is the document to hold us to. Operationally, uptime is checked continuously, backend errors raise an alert, and object storage is versioned so an accidental overwrite is recoverable.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              },
              {
                "uuid": "b06f3fe1-73d0-4590-88dc-d013e365f1b2",
                "control-id": "cp-9",
                "description": "What is your incident notification commitment? The commitment in our DPA governs, and it is the document to hold us to. Operationally, uptime is checked continuously, backend errors raise an alert, and object storage is versioned so an accidental overwrite is recoverable.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "http://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ],
                "links": [
                  {
                    "href": "https://www.filltrust.com/trust",
                    "rel": "reference",
                    "text": "Published answer"
                  }
                ]
              }
            ]
          }
        ]
      }
    ],
    "back-matter": {
      "resources": [
        {
          "uuid": "69b4804a-ca14-4795-a2d7-0b4c2a5eb007",
          "title": "Security overview",
          "rlinks": [
            {
              "href": "https://www.filltrust.com/security"
            }
          ]
        },
        {
          "uuid": "e9981841-2b14-48f8-94cf-73e3eafc2ac2",
          "title": "Data Processing Agreement",
          "rlinks": [
            {
              "href": "https://www.filltrust.com/legal/dpa"
            }
          ]
        },
        {
          "uuid": "fff0de21-c7ae-423c-81e3-fbfb11e04726",
          "title": "Sub-processor list",
          "rlinks": [
            {
              "href": "https://www.filltrust.com/legal/subprocessors"
            }
          ]
        },
        {
          "uuid": "8bbbc3c6-ea07-4827-befd-85d062ada859",
          "title": "Trust Center",
          "rlinks": [
            {
              "href": "https://www.filltrust.com/trust"
            }
          ]
        },
        {
          "uuid": "69bcad1c-190b-476d-9713-5adaa82ea5ab",
          "title": "Privacy policy",
          "rlinks": [
            {
              "href": "https://www.filltrust.com/privacy"
            }
          ]
        }
      ]
    }
  }
}