Loading Tropic...
Tropic ships agents for healthcare, finance, and public sector customers. We hold the certifications they need and the contract terms their legal teams actually sign.
Independently audited by Prescient Assurance. Reports available under NDA via [email protected].
Covered-entity and business-associate agreements available for Enterprise customers handling PHI.
EU Data Processing Addendum available. Sub-processor list published and monitored.
Currently in stage-two audit. Controls in production since Q4 2025.
No card data stored on Tropic infrastructure. Payment processing via Stripe / Razorpay.
Verifiable consumer requests honored within 30 days via [email protected].
TLS 1.3 in transit. AES-256 at rest (customer content, backups, logs). Per-tenant encryption keys on Enterprise.
Keys live in AWS KMS with automatic rotation. HSM-backed on Enterprise. BYOK via CMK on request.
SSO/SAML + SCIM. Role-based permissions. Every admin action logged with tamper-evident audit trail.
Multi-tenant SaaS (default), VPC single-tenant, on-premises, and air-gapped. Pick the isolation your compliance demands.
US, EU, UK, APAC regions available. Per-workspace residency pinning on Enterprise.
24/7 on-call. Customer notification within 72h of confirmed breach. Post-mortems published for every SEV-1.
The commitments that matter, written in plain English — not buried in a DPA.
Email [email protected] — you'll get all standard documents within one business day.
Read security overviewWe'll walk through your compliance checklist and help you pick the right deployment.