Vendor Security Summary.
Use Print (Ctrl+P / Cmd+P) to save as PDF, or send this page URL directly.
Platform Security Summary
TriPrism, Inc. / PhotoTouch, Inc.
Document Date: August 26, 2026
This document summarizes the security controls and compliance posture of the PhotoTouch platform.
It is intended for use by photographers and their enterprise clients (schools, venues, retailers,
event organizers) who require vendor security documentation.
Scope. PhotoTouch is one component of a client’s wider environment. This document
describes the controls we operate over that component: the platform itself, the photographs and customer
data it holds, and the people and systems with access to it. It does not describe the controls of the
other systems a client runs alongside it, of the photographer or organization acting as data controller,
or of a venue or retail partner’s own environment. Where a control is operated by a provider beneath
us rather than by us, it is identified that way rather than claimed as our own.
Rate limiting and automatic lockout on repeated failed login attempts
Sessions expire after a defined inactivity period
Authorization
Role-based access control (RBAC) with 10 distinct user roles
Granular three-tier permission system (Read / Write / Execute) with per-user overrides
Geographic scoping restricts data visibility to assigned organizational units
Administrative access follows the principle of least privilege
Read-only roles available for view-only access requirements
Personnel Security
Production access is held by a small, named group; background screening is required for anyone granted it
Workstations used for production access are password-protected and lock automatically after five minutes idle, with centrally managed endpoint protection
Formal security training annually, with quarterly phishing and social-engineering reminders; completion tracked and retained
Outbound Integration Control
Client-configured integrations must be documented before use: what is sent, where, by what transport, and for what purpose
The receiving organization returns a signed attestation before data flows, confirming encryption at rest and in transit, restricted access, purpose limitation, secure deletion, and 72-hour breach notification
Attestations expire after 365 days; an integration whose attestation lapses is disabled automatically rather than continuing to send
The signed record snapshots field mapping, purpose and masked endpoint as at signing, so later drift is visible against what was agreed
3. Audit Logging & Monitoring
All administrative actions are recorded in an append-only audit log (who, what, when, where, outcome)
Risk-based classification automatically flags unusual activity patterns for review
Real-time automated alerts for elevated and critical security events
Per-account activity logs accessible to account administrators
Audit logs retained for a minimum of 7 years
Login failure monitoring with configurable alerting thresholds
4. Vulnerability Management & Penetration Testing
A security agent runs continuously on the hosting platform, with real-time threat detection, malware prevention and automated remediation
A full automated vulnerability and malware scan of the server estate is performed daily
A PCI-standard external scan of the public perimeter is performed monthly
Platform dependencies are checked against a public vulnerability advisory database on every code change and on a scheduled weekly sweep, so an advisory published against a component that has not changed is still caught without waiting for the next release
Penetration testing is performed internally on a recurring basis, covering authentication and session handling, access control, tenant isolation, injection surfaces and public API endpoints
Testing runs against a full-stack environment with the alerting pipeline live, so the detection and alerting path is exercised by the test rather than assumed
A further internal test is scheduled for mid-September 2026, ahead of the next platform release
Findings from every source (scanning, testing and external report) are triaged, prioritized and tracked to remediation and closure in our internal issue management system
Independent third-party penetration testing has not been performed to date. Where a client requires an independent test, that is a conversation we are open to having rather than a capability we currently claim
5. Incident Response
Documented incident response plan covering identification, containment, eradication, recovery, and post-incident review
Critical security events automatically generate tracked incidents with response SLAs
Security incidents affecting customer data are communicated without undue delay, including within 72 hours where required by applicable law (for example GDPR Article 33)
Post-incident reviews conducted to identify root causes and implement preventive measures
Incident acknowledgment, investigation, and resolution tracked with full audit trail
6. Backup & Recovery
Automated database backups on regular schedule, stored in geographically separate off-site locations
Enterprise backup infrastructure with encryption at rest
File-level and system-level backups maintained independently of database backups
Recovery procedures tested periodically
Infrastructure designed with redundancy at network, compute, and storage layers
7. Endpoint & Infrastructure Security
Enterprise-grade endpoint cybersecurity with real-time threat detection, malware prevention, and automated remediation
Centrally managed endpoint protection with continuous monitoring
Database access restricted to application servers; no public access
Webhook signature verification on all inbound integration endpoints
SSRF protections on outbound API integrations (private IP ranges, internal hostnames, and metadata endpoints blocked)
CSRF protection on all form submissions
Input validation and output encoding to prevent injection attacks
Parameterized database queries
8. Data Privacy
Built-in GDPR tools: data search, export, and cascade-safe erasure with full audit trail
Automatic email and SMS suppression lists (bounce, complaint, opt-out processing)
Consent management with digital model release capture and customer-facing revocation
No biometric processing: no facial recognition, no biometric templates, no cross-photo identity matching
The platform conducts no third-party tracking of its own: no TriPrism-operated analytics property, advertising account or marketing pixel against customer traffic, no advertising or tracking cookies, and no session-replay, heatmap or session-recording tooling from any party
Photographers and partner organizations may install their own tags on their own storefronts, and control any data those tags collect. Marketing tags accept validated identifiers only (GA4, Google Tag Manager, Meta pixel, Google Ads conversion), so pasting a whole vendor snippet does not store or emit that snippet - only a recognized identifier is extracted from it and kept. Live chat is restricted to vendors on a maintained host allow-list of recognized chat providers, and no session-recording or heatmap product appears on it. Both are off unless a client enables them
Photographer controls their own data retention: the platform provides tools, photographer sets policy
Sub-processor list publicly disclosed with 30-day change notification commitment
Return & Deletion at End of Term
Data runs the retention term the client has configured or agreed, and is then securely removed; ending the relationship neither shortens nor extends that clock
On termination of an account, data is retained for 90 days to allow reactivation, then permanently deleted from production systems
Backup copies are purged on the same schedule as primary data, so a deletion is not undone by a restore
Audit logs, which may carry references to personal data, are retained for seven years to support contractual, security and regulatory requirements - the deliberate exception to the above
Earlier deletion may be requested at any time rather than waiting for the term to run
These are contractual obligations, set out at sections 10 and 12 of the Data Processing Agreement, which survives termination for the purposes that require it
Data Residency & Cross-Border Transfer
Image storage and the application database are United States-based for all accounts and all regions; there is no in-region data store
Puerto Rico and Guam: United States territories, so hosting for those accounts is domestic rather than a cross-border transfer; Puerto Rico's Citizen Information on Data Banks Security Act and Guam's own breach-notification requirements still apply
Canada: no adequacy regime under PIPEDA; transfers rely on contractual measures securing comparable protection, plus the transparency obligation to tell individuals their information is processed outside Canada. A privacy impact assessment precedes the transfer where Quebec's Law 25 applies
Mexico: transfer rests on the privacy notice given to the individual and on contractual measures binding the recipient to the same notice and purposes, under the Federal Law on the Protection of Personal Data Held by Private Parties
Australia: a cross-border disclosure under Australian Privacy Principle 8; reasonable steps are taken by contract to ensure overseas recipients handle personal information consistently with the APPs
New Zealand: the same basis under IPP 12 of the Privacy Act 2020
United Kingdom: UK GDPR and the Data Protection Act 2018, relying on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses
France and the wider EEA: EU GDPR, relying on the EU Standard Contractual Clauses together with supplementary technical measures (encryption in transit and at rest)
Japan: cross-border provision under Article 28 of the Act on the Protection of Personal Information, on the basis of contractual measures requiring equivalent protections
Text messaging to Australian and New Zealand numbers can be routed through an Australian carrier, at the client's election
9. Compliance Status
Framework
Status
SOC 2
Controls implemented and operating against the Trust Services Criteria; formal attestation not yet obtained. Control mapping published at admin.findyourpictures.com/legal/security §7.2
Platform controls designed to support compliance (controller obligations remain with each photographer)
CCPA/CPRA (California)
Platform controls designed to support compliance
COPPA (Children’s Privacy)
Platform controls designed to support compliance; photographer remains responsible for consent workflows
CAN-SPAM / TCPA
Platform controls designed to support compliance
PCI DSS
Via Certified Processors
Current Assurance Posture (As of August 26, 2026)
Controls are implemented and operating against the SOC 2 Trust Services Criteria and mapped to ISO/IEC 27001:2022 Annex A. The mapping is published in full, control area by control area, at admin.findyourpictures.com/legal/security §7.2. Formal attestation and certification have not been obtained; we are in the evidence-collection stage of a SOC 2 readiness program, with continuous control monitoring in place
Our incident response policy requires quarterly mock exercises and one annual live drill, and requires that drill records be retained
Vulnerability scanning and penetration testing are set out in full in §4 above: a continuously running security agent, a daily automated scan of the server estate, a monthly PCI-standard external perimeter scan, dependency advisory checks on every code change and weekly, and recurring internal penetration testing, with findings from every source tracked to closure
Independent third-party penetration testing has not been performed to date
Access and audit-log reviews run on the fixed calendar below, each producing a recorded reviewer, date, findings and action items
Our backup and recovery policy requires at least one documented restore test per year
Cyber insurance is currently under evaluation
Periodic Review Schedule
Review Type
Frequency
Audit Log Review
Every 30 days
Audit Log + Access Review
Every 90 days
Credential Rotation Review
Every 180 days
Platform Integration Audit
Annually (365 days)
Completing a review records the reviewer, the date, the findings and the action items arising, and
schedules the next review of that type automatically at its cadence. A review not completed by its
due date is marked overdue without manual intervention, and one more than seven days overdue is
escalated by email to the security owner.