Security
On this page
ToggleAuthentication
All requests to the TrustCloud API authenticate using a TrustCloud-generated JSON Web Token (JWT). This key is digitally-signed and can be set to expire or revoked at any time. By using a signed key, authentication and claims can be validated, and by decoupling API access from an individual user, API keys can be revoked without impacting the user’s ability to access TrustCloud.
Access Control
TrustCloud assigns all API Keys with a limited role of API_USER. This role is limited to the following permissions necessary to access the API endpoints in TrustCloud API.
Create | Read | Update | Delete | |
Controls | No | Yes | No | No |
Systems | No | Yes | No | No |
Tests | No | Yes | No | No |
Evidence | Yes | Yes | No | No |
TrustCloud API offers comprehensive logging features that provide insights into API calls, facilitating continuous monitoring and audit trails. This functionality is crucial for compliance requirements and enhances transparency across your IT operations.
Moreover, the TrustCloud API supports seamless scalability, allowing your organization to adapt as demands grow without compromising security. By leveraging the power of our advanced security measures, you can focus on innovation while TrustCloud safeguards your data integrity and privacy.