This is a transparency overview. It supplements, but does not replace, our Privacy Policy, Terms of Service, and Data Processing Addendum.
How TrustXP is built, where your data is stored, who processes it on our behalf, and the controls we use to keep it safe. Written for customers, prospective customers, and the security and privacy reviewers who evaluate us.
Last updated: 24 August 2026
This is a transparency overview. It supplements, but does not replace, our Privacy Policy, Terms of Service, and Data Processing Addendum.
TrustXP runs entirely on managed cloud infrastructure. We do not own or operate physical servers, and we do not run TrustXP in a customer's own environment.
| Component | Hosted by | Region | Address |
|---|---|---|---|
| Platform app - the dashboard your admins use | Vercel | Global edge network | platform.trustxp.com |
| Pulse app - where your people answer pulses | Vercel | Global edge network | pulse.trustxp.com |
| API and background processing | Railway | EU (Netherlands, EU West) | api.trustxp.com |
| Primary database | Railway managed PostgreSQL | EU (Netherlands, EU West) | Private network only |
Separate environments. Product demonstrations and internal testing never touch production. Our demo environment runs the same application code against its own database, its own API service, and its own identity provider instance, seeded exclusively with synthetic sample data. In that environment, outbound email is structurally disabled and no scheduled jobs run.
All of the below lives in the production PostgreSQL database described above.
| What | Examples | Why we hold it |
|---|---|---|
| Organization profile | Organization name, plan, time zone, pulse schedule settings | Configuring and running your workspace |
| Administrator accounts | Name, work email, identity-provider user ID, last sign-in | Signing your admins in and controlling what they can see |
| People who receive pulses | Name, work email, role, team, start date, active status | Knowing who to invite to each pulse |
| Pulse content | Pulse titles, schedules, status, question text and dimension | Running the survey itself |
| Responses | A 1-5 score, an optional written comment, the dimension, and a timestamp | The feedback your organization acts on, stored without a link to the person who wrote it (see section 3) |
| Scores and trends | Aggregated dimension scores, contributor counts, historical snapshots | Your dashboard, trend lines, and reporting |
| Alerts and follow-ups | Alert text, suggested playbook, owner, dismissed state | Flagging movements and tracking what you do about them |
| Email delivery events | Recipient address and delivery outcome (sent, delivered, bounced, complained) | Making sure invitations arrive, and suppressing addresses that bounce |
| Audit history | Who did what, when, in which organization | Security review and change tracking |
| Billing | Payment-processor customer and subscription identifiers, plan, status, billing period | Managing your subscription |
Anonymity is the reason people answer honestly, so it is enforced by how the system is built, not by a policy promise.
The practical guarantee: an administrator using TrustXP can see what their organization said, and cannot see who said it.
These are our subprocessors. Each is bound by a data processing agreement, and each publishes its own security and compliance documentation.
| Provider | What they do for us | What they see |
|---|---|---|
| Railway | Hosts our application servers and the primary database | All application data, at rest and in their infrastructure |
| Vercel | Hosts and delivers the three web applications | No stored customer data - static assets and request metadata only |
| Clerk | Authentication and identity | Administrator names, emails, and sign-in activity |
| Resend | Sends pulse invitation and reminder emails | Recipient email addresses and delivery outcomes |
| Stripe | Subscription billing and payments | Billing contact and payment details of the paying customer |
| MailerLite | Email list and newsletter delivery | Subscriber email addresses and signup tags. Data processed in EU (Germany and the Netherlands) |
We will update this list before adding a new subprocessor that handles customer personal data.
Your organization's data is stored and processed in the European Union (Netherlands). Both the application servers and the database sit in that region.
Two qualifications, stated plainly:
Where personal data is transferred outside the European Economic Area, we rely on the applicable providers' Standard Contractual Clauses and data processing addenda.
| Topic | Where to write |
|---|---|
| Privacy questions, data access or deletion requests | privacy@trustxp.com |
| Security concerns or vulnerability reports | security@trustxp.com |
We respond to privacy and security inquiries within the timeframes required by applicable law, and we ask that vulnerability reports be sent to us before they are disclosed publicly.
Download the documents your security or procurement team needs to evaluate TrustXP.