Data Processing Addendum
How Vikavi Security LLC processes personal data on behalf of customers when providing the TrustFix non-human identity security service.
Pending legal counsel review. This document is a working draft provided for transparency. It has not yet been reviewed by qualified legal counsel and is not yet a binding agreement. Do not rely on it as legal advice. The definitive, executed version will be made available before it takes effect.
1. Introduction and scope
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", "Controller") and Vikavi Security LLC, a Delaware limited liability company operating the TrustFix service ("TrustFix", "Processor", "we"), under which TrustFix provides non-human identity (NHI) security scanning, attestation, and remediation services (the "Service").
This DPA applies where, and only to the extent that, TrustFix processes personal data on behalf of the Customer in the course of providing the Service, and where that processing is subject to data protection laws such as the EU General Data Protection Regulation (GDPR), the UK GDPR, or the California Consumer Privacy Act (CCPA/CPRA). Where this DPA conflicts with the underlying agreement on matters of data protection, this DPA controls.
2. Roles of the parties
For the personal data processed to deliver the Service, the Customer acts as the Controller (or, where the Customer is itself a processor for a third party, as a processor) and determines the purposes and means of processing. TrustFix acts as the Processor and processes personal data only on documented instructions from the Customer, including those set out in the agreement, this DPA, and the Customer’s configuration of the Service.
Where TrustFix processes a limited set of data as an independent controller — for example, account and billing records, and operational telemetry used to secure and improve the Service — that processing is governed by the TrustFix Privacy Policy rather than this DPA.
3. Nature and purpose of processing
TrustFix is an NHI security platform. The core of what we process is configuration and identity metadata — not the contents of your applications or your end-users’ records. We process data solely to detect machine-identity misconfigurations, generate and track remediation, produce signed attestations and audit receipts, and operate, secure, and support the Service.
- Identity and access metadata: IAM roles, trust policies, policy attachments, service accounts, OIDC/workload identity bindings, and similar non-human identity configuration read via Customer-authorized, read-only access.
- Source-control metadata: CI/CD workflow definitions (for example, .github/workflows) and repository metadata. We do not read application source code.
- Service usage records: scans initiated, findings generated, remediation pull requests created, attestations issued, and the tamper-evident, append-only audit ledger of these actions.
- Account and contact data: names, work email addresses, and organization details of the authorized users your administrators invite.
4. Categories of data subjects and personal data
The personal data processed under this DPA is limited and, by design, minimal. Because TrustFix operates on machine-identity and configuration metadata rather than business records, the personal data we encounter is principally that of the Customer’s own authorized personnel.
- Data subjects: the Customer’s administrators, engineers, and other authorized users of the Service; and, incidentally, individuals named in identity configuration or commit metadata (for example, the author of a workflow file).
- Categories of personal data: names, work email addresses, user and organization identifiers, authentication and session records, IP addresses and request logs, and any personal identifiers that appear within the identity/configuration metadata the Customer chooses to connect.
- No special categories: the Service is not designed to process special-category (sensitive) personal data, and the Customer agrees not to route such data through the Service.
5. Customer instructions and obligations
TrustFix will process personal data only on the Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by applicable law (in which case TrustFix will inform the Customer of that legal requirement before processing, unless the law prohibits such notice).
The Customer is responsible for establishing a lawful basis for the processing, for the accuracy of the data it connects to the Service, and for ensuring it has the right and authorization to grant TrustFix access to the cloud accounts and repositories it connects.
6. Confidentiality
TrustFix ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and are granted access on a least-privilege, need-to-know basis. Access to Customer data is logged.
7. Security measures
TrustFix maintains technical and organizational measures appropriate to the risk, designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include, at minimum:
- Encryption of data in transit using TLS, and encryption of data at rest for stored Customer data.
- Read-only access to connected cloud accounts using temporary, short-lived credentials (for example, AWS STS via a customer-created cross-account role). We do not store long-lived cloud access keys.
- Strict tenant isolation: one Customer’s data is never accessible to another Customer.
- A tamper-evident, append-only, cryptographically signed audit ledger of scans, findings, remediations, and attestations.
- Least-privilege internal access controls, authentication safeguards including multi-factor authentication for administrative access, and centralized logging and monitoring.
- A documented vulnerability-management and patching process, and periodic review of these measures.
8. Sub-processors
The Customer authorizes TrustFix to engage sub-processors to support the delivery of the Service. TrustFix imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for each sub-processor’s performance of its obligations.
A current list of sub-processors, organized by category (such as cloud hosting and transactional email), is maintained on the TrustFix Sub-processors page. TrustFix will provide a mechanism for the Customer to be notified of, and reasonably object to, the addition of a new sub-processor before that sub-processor begins processing Customer personal data.
9. Data-subject rights
Taking into account the nature of the processing, TrustFix will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data-subject rights — including rights of access, rectification, erasure, restriction, portability, and objection.
Where a data subject contacts TrustFix directly regarding data processed on a Customer’s behalf, TrustFix will, unless legally prohibited, promptly forward the request to the relevant Customer and will not respond to the request itself except on the Customer’s instructions.
10. Personal-data breach notification
TrustFix will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data, and will provide the Customer with information reasonably available to it to assist the Customer in meeting any breach-notification obligations under applicable law. Notification of a breach is not an acknowledgment of fault or liability.
11. International transfers
TrustFix and its sub-processors may process personal data in the United States and in other jurisdictions where TrustFix or its sub-processors operate. Where personal data subject to the GDPR or UK GDPR is transferred to a country that has not received an adequacy decision, TrustFix relies on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), which are incorporated into this DPA by reference and applied where required.
12. Audit and compliance
TrustFix will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality obligations, and limits designed to protect the security and confidentiality of other customers’ data. Where available, TrustFix may satisfy audit requests by providing relevant third-party reports or its signed attestation receipts.
13. Term, return, and deletion
This DPA remains in effect for as long as TrustFix processes personal data on the Customer’s behalf. On expiry or termination of the Service, and at the Customer’s choice, TrustFix will delete or return all Customer personal data and delete existing copies, unless retention is required by applicable law. By default, Customer data is deleted within 30 days of account termination; certain audit-ledger records may be retained for the period required to evidence the integrity of past attestations or to comply with legal obligations.
14. Contact
Vikavi Security LLC (operating as TrustFix), a Delaware limited liability company, headquartered in the Greater St. Louis area, United States.
For data-protection inquiries relating to this DPA, contact security@trustfix.dev. For general inquiries, contact hello@trustfix.dev.