Rapid Deploy and Customer Data.

Last modified on JAN 1, 2026

Trundl’s Rapid Deploy operating model (commonly referred below as “the Platform”) is built for organizations that rely on secure, reliable integrations, migrations, and configuration automation. For any security or data confidentiality concerns, we aim to explains how Trundl protects your data, how Trundl operates the Rapid Deploy Platform, and what you can expect from Trundl as your technology enablement partner.

Scope & Overview

Platform core capabilities:

  • Safe, repeatable custom configuration, deployment and rollback automation.
  • Large-scale migrations and ongoing, secure, bi‑directional synchronization across tools, including issues, tickets, tasks, and related metadata.
  • Discovering, analyzing, and preparing source environments for migration or integration.
  • Centralized observability of jobs, logs, and system health.

Hosting & Key Subprocessors

  • Infrastructure hosting: Amazon Web Services (AWS)
  • AI features: OpenAI (Business / Enterprise plan, including ChatGPT Business and ChatGPT Enterprise), Anthropic (Enterprise Plan)
  • Used for selected AI‑driven features (e.g., suggestions, mappings, summaries), with strict controls on what data is sent and how it is handled.

Hosting & Key Subprocessors

Security

Application & Data Security 

  • Credential protection: API tokens and external service credentials are encrypted at rest using strong industry-standard encryption (e.g., AES‑256). Credentials are never stored in plaintext in application logs or source code. Support for credential rotation and scoped access per integration.
  • Authentication & sessions: Authentication uses secure, modern standards (e.g., token-based sessions). Passwords (if used) are hashed with strong, one-way hashing algorithms (e.g., bcrypt). Single Sign-On (SSO) options (such as SAML or OIDC) can be supported for enterprise customers.
  • Transport security: All communication with the Platform uses HTTPS with modern TLS. Secure protocol versions and strong cipher suites are enforced. Connections to AWS services and OpenAI/Anthropic APIs are also made over TLS‑secured channels.
  • Secrets management: Internal secrets (database credentials, encryption keys, API keys, including the OpenAI/Anthropic API key) are stored in AWS‑managed secret storage. Access to secrets is tightly controlled via IAM policies and is audited.
  • Web security controls: AWS Web Application Firewall (WAF) helps protect against common attack classes (e.g., SQL injection, cross‑site scripting). Rate limiting and abuse detection at the edge. Strict controls on cross‑origin requests and other browser-based risks.
Infrastructure Security
  • Cloud-native architecture on AWS: The underlying Rapid Deploy platform runs on AWS using containerized services and managed databases (e.g., Amazon RDS, ECS/EKS). Trundl leverages VPCs, Security Groups, IAM roles, and managed encryption as standard
  • Network segmentation: Public access is limited to the Platform UI and external APIs (typically via AWS Application Load Balancers and/or Amazon CloudFront). Databases, internal services, and message queues reside in private subnets and are not directly exposed to the internet.
  • Hardened services: Workloads run in isolated containers with least‑privilege permissions. Base images and dependencies are regularly updated and patched.
  • Access control: Operational access to production AWS environments is restricted to a small number of authorized personnel using strong authentication and least‑privilege IAM roles. All administrative and privileged operations are logged and monitored (e.g., via AWS CloudTrail and CloudWatch).

Data Protection & Privacy

Includes:

  • Data Handling and OpenAI (ChatGPT Business / Enterprise), Anthropic (Enterprise) Privacy
  • Data Processed Within Platform (Hosted on AWS)
Platform process:
  • Work items and related metadata (e.g., issues, tasks, tickets, fields, comments, and optionally attachments) to perform syncs, migrations, deployments, and discovery.
  • Configuration data such as connection details, mapping rules, deployment definitions, and job configurations.
  • Discovery and analytics information about your environments (e.g., project structures, usage patterns).
  • Operational data such as logs and metrics required to operate and troubleshoot the platform.
This data is stored and processed on AWS, with tenant isolation and encryption as described in this Trust Center.
Use of OpenAI (Business / Enterprise, Including ChatGPT Business) and Anthropic (Enterprise plan)
The Platform uses both OpenAI’s Business/Enterprise and Anthropic (Enterprise offerings only for specific, opt‑in AI features, such as:
  • Generating or suggesting mappings, transformations, or configuration patterns.
  • Producing summaries or explanations
  • Providing AI-assisted insights to help design or validate configurations.
When these AI features are used:
  • Only limited, scoped text or metadata is sent to OpenAI/Anthropic, strictly what is required for that feature.
  • The Platform does NOT send:Customer passwords, API keys, or other secrets, Database connection strings, Unnecessary personal data beyond what the feature requires.
  • Where practical, data passed to OpenAI/Anthropic is minimized and may be pseudonymized or partially redacted.
How OpenAI Treats the Platform Data:

The Platform is based on OpenAI’s Enterprise Privacy commitments (https://openai.com/enterprise-privacy/):

  • There is NO training on your business data by default: Prompts and responses sent from the Platform to OpenAI under Business/Enterprise plans are not used to train or improve OpenAI’s public models by default.
  • You own your inputs and outputs (where allowed by law): Your organization retains ownership of prompts (inputs) and responses (outputs) generated via the Platform’s AI features.
  • Enterprise controls and retention: OpenAI provides enterprise controls over data retention (for example, ChatGPT Enterprise), Within the Platform, AI‑related logs and outputs stored on AWS follow our own retention policies, aligned with your contractual and regulatory requirements.
  • Access control & authentication: OpenAI supports enterprise-level authentication (e.g., SAML SSO) and fine‑grained access controls. Within the Platform, administrators can control; Which users or roles may access AI features, Which environments are allowed to call OpenAI, What types of data are excluded from prompts.
  • Security & compliance: OpenAI’s enterprise offerings are designed with; SOC 2–aligned controls, AES‑256 encryption at rest, TLS 1.2+ encryption in transit.
Where Your Data Lives
  • Core Platform data (configurations, logs, states, discovery results) is stored on AWS in your designated region(s).
  • AI processing occurs via encrypted API calls from the Platform (in AWS) to OpenAI.
  • OpenAI does not have direct access to your AWS databases or infrastructure.
  • Only minimal, scoped payloads are transmitted for each AI feature invocation.
Customer Control Over AI Usage
You can:
  • Enable or disable AI-powered features globally, or by environment/role (where supported).
  • Define internal rules for what data is allowed in prompts.
  • Request stricter minimization of data sent to OpenAI as part of your security and privacy requirements.
For more information on OpenAI’s enterprise privacy commitments, see: 
Enterprise privacy at OpenAI
How Anthropic Treats the Platform Data:
The Platform accesses Anthropic (Claude) through Anthropic’s API under Anthropic’s Commercial Terms of Service
There is NO training on business data
  • Prompts (inputs) and responses (outputs) sent from the Platform to Anthropic via the API are not used to train Anthropic’s models.
  • Under Anthropic’s Commercial Terms, business data submitted through the API is excluded from model training.
  • The Platform accesses Claude programmatically and exposes no end-user feedback mechanism, so there is no path by which Trundl or Customer data would be contributed to model improvement.
Trundl owns inputs and outputs (where allowed by law)
  • Under Anthropic’s Commercial Terms, and to the extent permitted by law, Trundl retains ownership of prompts (inputs), and Anthropic assigns to Trundl its rights in the responses (outputs) generated via the Platform’s AI features.
Data retention
  • Prompts and responses sent via Anthropic’s API are automatically deleted from Anthropic’s backend within 30 days of receipt or generation, except where retention is required to enforce Anthropic’s Usage Policy or to comply with law.
  • Anthropic does not persist API inputs and outputs beyond this window under the standard commercial arrangement.
  • Within the Platform, AI-related logs and outputs stored on AWS follow our own retention policies, aligned with Trundl/Customer contractual and regulatory requirements.
Brokered access architecture
  • The Platform does not integrate AI tools directly into the customer’s applications or infrastructure. All calls to Anthropic are routed through a controlled server layer that sits between the Platform and the AI provider’s API. This design allows the Platform to: Enforce, at a single point, which data is permitted to be included in prompts, and redact or exclude the rest; Prevent client-side and third-party direct access to the AI integration or API credentials; Centrally log, monitor, and rate-limit all AI requests and responses; Apply the Platform’s own retention and access-control policies to logs and outputs stored on AWS, independent of the provider.
Access control & authentication
  • Access to the Platform’s AI features is governed by the Platform’s own controls rather than a shared AI-tool console. Administrators can control: Which users or roles may access AI features; Which environments and services are permitted to call the AI provider’s API; Who may configure the server layer and access the API credentials; What types of data are excluded from prompts.
Security & compliance
  • Anthropic’s enterprise offerings are designed with: SOC 2 Type I and Type II attestation, ISO/IEC 27001:2022 (information security), and ISO/IEC 42001:2023 (AI management systems) certification; HIPAA-ready configuration, with a Business Associate Agreement (BAA) available for eligible services; AES‑256 encryption at rest; TLS 1.2+ encryption in transit.
  • Compliance reports and documentation are available through Anthropic’s Trust Center: Anthropic Trust Center

Encryption

  • In transit: All data between your systems and the Platform is encrypted using TLS. Calls between the Platform and AWS services, and between the Platform and OpenAI/Anthropic, are also encrypted.
  • At rest: Databases, volumes, and object storage on AWS are encrypted at rest (e.g., AWS KMS with AES‑256). Backups and snapshots follow the same encryption standards.
  • Credentials & secrets: Integration credentials, API keys (including OpenAI), and other secrets are stored in encrypted form using AWS secret management services.
Access to Customer Data
  • Access is limited to authorized personnel and only for: Resolving support requests; Investigating and mitigating incidents.
  • All such access is logged and governed by internal policies.
  • OpenAI and Anthropic receive only minimal, scoped data required to provide AI features, and do not have access to the Platform’s AWS infrastructure.

Compliance & Governance

Security Governance
  • Security‑by‑design across the Platform product lifecycle.
  • AI-related features undergo security and privacy review before production release.
  • AWS’s compliance posture (e.g., ISO 27001, SOC, PCI) forms part of our underlying control environment.
Policies & Practices
  • Secure coding practices aligned with OWASP guidelines.
  • Formal change management for production deployments and AWS configuration changes.
  • Regular review of access rights, monitoring, and logging configurations.
Compliance Posture
  • Controls designed with the expectations of standards such as ISO 27001 and SOC2 in mind.
  • Data protection aligned with applicable privacy laws (e.g., GDPR).
  • Data Processing Agreements (DPAs) and security exhibits can list AWS and OpenAI/Anthropic as sub-processors where applicable.

Availability, Reliability & Performance

Platform Availability 
  • The Platform is designed on AWS for high availability suitable for business‑critical workloads.
  • Enterprise SLAs: Can be defined contractually.
  • Redundancy & fault tolerance: Highly available application services and multi‑AZ databases, Stateless services with horizontal scaling.
  • Scalability: AWS autoscaling supports fluctuating loads (e.g., migration bursts or sync spikes), Rate limits and quotas protect the platform and external APIs (including OpenAI).
Monitoring & Incident Response
  • Monitoring: Application performance, infrastructure health, job throughput, and failures are monitored. Centralized logging of application and infrastructure events, including AI usage where applicable.
  • Alerting: Automated alerts for errors, degraded performance, abnormal activity, and potential AI misuse.
  • Incident response: Documented incident response process (detection, triage, containment, remediation, communication). Post‑incident reviews for significant events.

Platform-Specific Security & Controls

The Platform and Sync Capabilities:
  • Secure orchestration: Sync and migration jobs run on AWS and strictly follow configured scopes and permissions. Clear separation between credentials, mapping rules, and execution.
  • Mappings & transformations: Mappings are centrally managed and can be versioned. Validation and “dry‑run” options are supported. Optional OpenAI/Anthropic-powered mapping suggestions use minimal metadata (no secrets).
  • Auditability: Detailed logs for items processed, changes applied, errors, and conflicts. Traceability to the user or configuration that triggered each operation.
The Platform and Deployment Capabilities
  • Controlled deployments: Deployments are performed via dedicated AWS-based services with validations and optional approvals. Rollback to previous known‑good states is supported.
  • Change tracking: Every deployment is logged with configuration, environment, and initiating user or pipeline.
  • Optional AI assistance: OpenAI/Anthropic can be used to suggest templates or configuration changes. Prompts exclude credentials or highly sensitive data.
The Platform and Discovery Capabilities
  • Safe analysis: Read‑oriented by design; operates under permissions you configure in your systems. Focused on metadata, structures, and usage patterns.
  • Data minimization: Collection limited to what is needed for assessment, optimization, and migration planning. Collected data is stored and protected on AWS.
  • AI‑enhanced insights (optional): Optional use of OpenAI/Anthropic to summarize findings or highlight patterns from discovery data (without credentials).
  • Reporting & export: Discovery outputs can be exported and reviewed for planning and governance.

Data Residency & Regional Options

  • Primary hosting regions: The Platform is hosted in selected AWS regions. Region choice can reflect your residency and regulatory needs.
  • Data location: Customer data is stored and processed in the AWS region(s) agreed in your contract, with limited cross‑region replication for resilience where applicable.
  • AI data residency: OpenAI/Anthropic may process data in its own infrastructure locations under the terms described at: Enterprise privacy at OpenAI; Home | Anthropic Privacy Center. The Platform minimizes data sent to OpenAI/Anthropic and can document data flows and regions during security due diligence.

Shared Responsibility Model

Trundl Responsibilities
  • Securing the platform and AWS infrastructure.
  • Managing encryption, access controls, logging, and monitoring.
  • Governing and securing the OpenAI/Anthropic integration.
  • Meeting defined availability and incident response commitments.
Customer Responsibilities
  • Managing identities and access (including SSO/IdP).
  • Protecting credentials used for Platform integrations.
  • Defining scopes, mappings, deployment rules, discovery scopes, and retention policies.
  • Establishing internal policies for AI usage and sensitive data handling.

Contact & Security Requests