generated: '2026-09-02' method: searched source: https://www.trisotech.com/security/ url: https://www.trisotech.com/security/ name: Trisotech Cloud security and compliance page summary: >- Trisotech publishes a single security page rather than a trust centre. It names one certification the company itself holds (SOC 2 Type II) and two it inherits from its hosting provider (ISO/IEC 27001:2013 and SOC 3, both Google Cloud), states data residency in Quebec, and describes its authentication and encryption posture. No report is downloadable and there is no NDA-gated document portal. certifications: - name: SOC 2 Type II scope: Trisotech Cloud held_by: Trisotech framework: AICPA SSAE 18 / SOC for Service Organizations statement: >- "achieved SOC 2 Type II compliance in accordance with American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations also known as SSAE 18" report_available: false self_attested: true - name: ISO/IEC 27001:2013 scope: Data center held_by: Google Cloud (hosting provider) statement: >- "Trisotech guarantees that its data center provider complies with the ISO 27001:2013 norm" report_available: via the Google Cloud compliance portal note: Inherited, not a certification of Trisotech itself. - name: SOC 3 scope: Data center held_by: Google Cloud (hosting provider) report_available: via the Google Cloud compliance portal note: Inherited, not a certification of Trisotech itself. data_residency: region: Quebec, Canada cloud: Google Cloud legal_basis: - Canadian federal privacy law - Quebec provincial privacy act security_posture_claims: - Encryption in transit via SSL/HTTPS for all customer communications - One-way hashed password storage - SAML 2.0 and OpenID Connect authentication for user sign-in related_documentation: - name: Secure Configuration Guide url: https://cloud.trisotech.com/help/admin/secure-configuration-guide.html - name: Administration security settings url: https://cloud.trisotech.com/help/admin/security.html not_claimed: - HIPAA Business Associate Agreement - FedRAMP - PCI DSS - ISO 27001 held by Trisotech itself - ISO 27017 / 27018 / 27701 - Downloadable audit reports or a subprocessor list note_on_healthcare: >- Trisotech sells a Healthcare Feature Set with CDS Hooks and SMART on FHIR endpoints, but the security page does not mention HIPAA, a BAA, or PHI handling. That is a notable gap for a buyer in that market and is recorded here as an absence, not as a failure. evidence: - url: https://www.trisotech.com/security/ status: 200 - url: https://cloud.trisotech.com/help/admin/secure-configuration-guide.html status: 200 - url: https://cloud.trisotech.com/help/admin/security.html status: 200