This policy is part of the TrustPoint Analytics website terms and may be incorporated into accepted services where applicable. Read it together with any Accepted Scope or signed agreement.
1. Confidentiality commitment
TrustPoint treats nonpublic client, project, sample, pricing, method, and report information as confidential and uses it to evaluate, perform, administer, secure, document, and enforce the requested service. This commitment is subject to the Accepted Scope, signed agreements, client authorization, legal requirements, and the exceptions below.
2. Permitted access and disclosure
- Personnel and providers with a business need to perform or support the service.
- Laboratories, consultants, couriers, hosting providers, and professional advisers subject to applicable duties or contractual restrictions.
- A recipient authorized by the client, including a public COA registry when authorized.
- Authorities or parties when required by law or reasonably necessary to address safety, fraud, misconduct, legal process, or legal claims.
- A successor or transaction participant subject to appropriate confidentiality during a business transfer or financing.
3. Security approach
TrustPoint uses reasonable administrative, technical, and organizational measures appropriate to the information and service, which may include access limitation, authenticated systems, encryption in transit where supported, backups, logging, vendor review, retention controls, and incident procedures. Specific controls may change as technology, risk, providers, and operations evolve.
4. No absolute guarantee
No system, laboratory, courier, email, network, or storage method is completely secure. TrustPoint does not guarantee that unauthorized access, loss, delay, corruption, or disclosure will never occur. Clients should minimize submitted information and avoid sending secrets or sensitive personal data that are unnecessary for the project.
5. Client security responsibilities
- Use accurate contact information and protect submission, report, invoice, and verification identifiers.
- Verify recipients before forwarding confidential reports or links.
- Do not send passwords, full payment-card data, government identifiers, patient records, or protected health information.
- Notify TrustPoint promptly of suspected compromise, misdirected communications, fraudulent reports, or unauthorized access.
- Maintain independent copies of client-provided records and final deliverables.
6. Incident response
TrustPoint evaluates suspected security events, takes proportionate containment and remediation steps, preserves relevant records where appropriate, and provides legally required notices. Not every unsuccessful attempt, service interruption, spam message, or non-sensitive event constitutes a reportable breach.
7. Reporting a concern
Use the Contact page and select “Security concern.” Do not include exploit code, credentials, sensitive personal information, or confidential third-party data in the initial message. TrustPoint does not authorize testing, probing, scanning, or access beyond what applicable law allows without prior written permission.