TriPrism, Inc. / PhotoTouch, Inc.
Last Updated: August 25, 2026
Security is fundamental to the PhotoTouch platform. We implement layered security controls across infrastructure, application, and operational processes to protect the personal data and photographs entrusted to us by photographers and their customers.
This page provides an overview of our security practices. For questions or to request detailed security documentation, contact security@triprism.com.
Scope of this page. PhotoTouch is one component of a client’s wider environment, and this page describes the controls we operate over that component: the platform itself, the photographs and customer data it holds, and the people and systems with access to it. It does not describe the controls of the other systems a client runs alongside it, of the photographer or organization acting as data controller, or of a venue or retail partner’s own environment. Where a control is operated by a provider beneath us rather than by us, it is identified that way in §7.2 rather than claimed as our own.
| Framework | Status |
|---|---|
| SOC 2 | Controls implemented and operating against the Trust Services Criteria. Formal attestation not yet obtained; the control mapping is published in §7.2 below |
| ISO/IEC 27001:2022 | Controls mapped to Annex A. Not certified; the mapping is published in §7.2 below |
| GDPR (EU) | Platform controls designed to support compliance: DPA, data subject rights tools, sub-processor disclosure, breach notification procedures |
| CCPA/CPRA (California) | Platform controls designed to support compliance: no sale of personal information, consumer rights tooling available |
| COPPA (Children’s Privacy) | Platform controls designed to support compliance: photographer responsible for parental consent; no direct collection from children |
| CAN-SPAM / TCPA | Platform controls designed to support compliance: suppression lists, opt-out mechanisms, sending hour controls |
| PCI DSS | Payment card data handled by PCI Level 1 certified payment processors; no card data is stored on our servers |
Third-party provider certifications are available through vendor trust portals. Platform assurance inquiries: security@triprism.com.
This is the mapping referred to above. It sets out, control area by control area, where our controls sit against the SOC 2 Trust Services Criteria and against ISO/IEC 27001:2022 Annex A, and whether the control is operating today. It describes our own controls against those frameworks. It is not an assessment by anyone else, and it is not a certification: no SOC 2 report and no ISO/IEC 27001 certificate has been obtained.
| Control area | SOC 2 TSC | ISO/IEC 27001:2022 Annex A | Status |
|---|---|---|---|
| Security governance & policy | Control environment (CC1.1–CC1.5) | Policies for information security (A.5.1); roles and responsibilities (A.5.2); segregation of duties (A.5.3); management responsibilities (A.5.4) | In place |
| Risk assessment | Risk assessment (CC3.1–CC3.4) | Threat intelligence (A.5.7) | In place |
| Logical access & least privilege | Logical access controls (CC6.1–CC6.3) | Access control (A.5.15); access rights (A.5.18); privileged access rights (A.8.2) | In place |
| Authentication & MFA | Logical access security (CC6.1) | Secure authentication (A.8.5) | In place |
| Transmission security | Transmission and movement of information (CC6.7) | Network security (A.8.20); security of network services (A.8.21); use of cryptography (A.8.24) | In place |
| Boundary & egress protection | Protection against external threats (CC6.6) | Network security (A.8.20); segregation of networks (A.8.22); web filtering (A.8.23) | In place |
| Audit logging & monitoring | Monitoring for anomalies (CC7.2) | Logging (A.8.15); monitoring activities (A.8.16) | In place |
| Periodic access & log review | Ongoing evaluations of controls (CC4.1); access modified and removed (CC6.2–CC6.3) | Review of access rights (A.5.18); management of authentication information (A.5.17) | In place |
| Vulnerability management | Detection of vulnerabilities and configuration change (CC7.1) | Management of technical vulnerabilities (A.8.8) | In place |
| Penetration testing | Evaluations of controls (CC4.1) | Independent review of information security (A.5.35) | Internal |
| Secure development | Change management (CC8.1) | Secure development life cycle (A.8.25); secure coding (A.8.28); separation of development, test and production (A.8.31) | In place |
| Change management | Change management (CC8.1) | Change management (A.8.32); configuration management (A.8.9) | In place |
| Supplier & sub-processor management | Vendor and business partner risk (CC9.2) | Information security in supplier relationships (A.5.19); supplier agreements (A.5.20); ICT supply chain (A.5.21) | In place |
| Incident management | Incident evaluation and response (CC7.3–CC7.4) | Incident management planning (A.5.24); assessment and decision (A.5.25); response (A.5.26); learning from incidents (A.5.27); collection of evidence (A.5.28) | In place |
| Backup, recovery & continuity | Recovery from incidents (CC7.5); availability, recovery infrastructure (A1.2) | Information backup (A.8.13); security during disruption (A.5.29); ICT readiness for continuity (A.5.30) | In place |
| Personnel screening | Commitment to competence and accountability (CC1.4–CC1.5) | Screening (A.6.1); terms and conditions of employment (A.6.2) | In place |
| Endpoint & device controls | Unauthorized software and configuration (CC6.8) | User endpoint devices (A.8.1); protection against malware (A.8.7) | In place |
| Information transfer & integration approval | Transmission and disposal of information (CC6.7) | Information transfer (A.5.14); data masking (A.8.11) | In place |
| Security awareness & personnel | Communication of security commitments (CC2.1–CC2.3) | Information security awareness, education and training (A.6.3) | In place |
| Privacy & personal-data protection | Privacy criteria (P1–P8); confidentiality (C1.1) | Privacy and protection of personal information (A.5.34) | In place |
| Retention & secure deletion | Retention and disposal (P4.2–P4.3) | Information deletion (A.8.10) | In place |
| Physical & environmental security | Physical access controls (CC6.4–CC6.5) | Physical security controls (A.7.1–A.7.14) | Inherited |
| Independent third-party attestation | SOC 2 report | ISO/IEC 27001 certificate | Not obtained |
In place means the control is implemented and operating. Internal means the activity is performed, but by us rather than by an independent third party. Inherited means the control is operated by the hosting provider under its own certifications rather than by us. Not obtained means exactly that.
If you discover a security vulnerability in the PhotoTouch platform, we encourage responsible disclosure. Please report vulnerabilities to:
Please include a description of the vulnerability, steps to reproduce, and any supporting evidence. We will acknowledge receipt within 2 business days and work to address confirmed vulnerabilities promptly. We ask that you not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.
For security inquiries, audit requests, or to report a concern:
Need to share our security posture with a client or partner? Download a printable summary of our platform security controls.
View & Download SummaryOpens a print-ready page. Use your browser’s Print function (Ctrl+P / Cmd+P) to save as PDF.
© 2026 TriPrism, Inc. All rights reserved.
Terms of Use • Privacy Policy • Sub-Processors • DPA • RoPA • Back to Login