Find Your Pictures

Platform Security Summary

TriPrism, Inc. / PhotoTouch, Inc.

Document Date: August 26, 2026

This document summarizes the security controls and compliance posture of the PhotoTouch platform. It is intended for use by photographers and their enterprise clients (schools, venues, retailers, event organizers) who require vendor security documentation.

Scope. PhotoTouch is one component of a client’s wider environment. This document describes the controls we operate over that component: the platform itself, the photographs and customer data it holds, and the people and systems with access to it. It does not describe the controls of the other systems a client runs alongside it, of the photographer or organization acting as data controller, or of a venue or retail partner’s own environment. Where a control is operated by a provider beneath us rather than by us, it is identified that way rather than claimed as our own.

For the full security overview, visit admin.findyourpictures.com/legal/security. For detailed documentation, contact security@triprism.com.

1. Service Overview

ItemDescription
ServiceCloud-based photography business management platform (event management, file storage, customer communications, order processing, reporting)
DeploymentCloud-hosted; no on-premise installation required
Data Center LocationUnited States
Photo StorageLiquidWeb-hosted object storage (S3-compatible) with server-side encryption
Payment ProcessingDelegated to PCI Level 1 certified payment processors; no card data is stored on the platform
Status Pagestatus.triprism.com

2. Data Protection & Access Control

Encryption

Authentication

Authorization

Personnel Security

Outbound Integration Control

3. Audit Logging & Monitoring

4. Vulnerability Management & Penetration Testing

5. Incident Response

6. Backup & Recovery

7. Endpoint & Infrastructure Security

8. Data Privacy

Return & Deletion at End of Term

Data Residency & Cross-Border Transfer

9. Compliance Status

FrameworkStatus
SOC 2Controls implemented and operating against the Trust Services Criteria; formal attestation not yet obtained. Control mapping published at admin.findyourpictures.com/legal/security §7.2
ISO/IEC 27001:2022Controls mapped to Annex A; not certified. The Annex A mapping is published at admin.findyourpictures.com/legal/security §7.2
GDPR (EU)Platform controls designed to support compliance (controller obligations remain with each photographer)
CCPA/CPRA (California)Platform controls designed to support compliance
COPPA (Children’s Privacy)Platform controls designed to support compliance; photographer remains responsible for consent workflows
CAN-SPAM / TCPAPlatform controls designed to support compliance
PCI DSSVia Certified Processors

Current Assurance Posture (As of August 26, 2026)

Periodic Review Schedule

Review TypeFrequency
Audit Log ReviewEvery 30 days
Audit Log + Access ReviewEvery 90 days
Credential Rotation ReviewEvery 180 days
Platform Integration AuditAnnually (365 days)

Completing a review records the reviewer, the date, the findings and the action items arising, and schedules the next review of that type automatically at its cadence. A review not completed by its due date is marked overdue without manual intervention, and one more than seven days overdue is escalated by email to the security owner.

10. Legal Documentation

The following documents are publicly available:

DocumentURL
Privacy Policyadmin.findyourpictures.com/legal/privacy
Terms of Useadmin.findyourpictures.com/legal/terms
Data Processing Agreementadmin.findyourpictures.com/legal/dpa
Security Overviewadmin.findyourpictures.com/legal/security
Sub-Processor Disclosureadmin.findyourpictures.com/legal/subprocessors

11. Contact

PurposeContact
Security Inquiriessecurity@triprism.com
Vulnerability Disclosuresecurity@triprism.com
Platform Statusstatus.triprism.com