TRooGTM

Security

An honest account of what's actually built today — not a compliance-certification claim. We haven't completed a SOC 2 or ISO 27001 audit; if that's a requirement for your organization, email support@troogtm.com and we'll tell you where things stand.

Sending isolation

Outbound email sends through our own managed mailbox pool, never a customer's primary domain — a reputation issue in the pool is isolated from any one customer's own sending reputation.

Audit trail

Every autopilot action (budget reallocation, campaign changes) is written to an append-only decision log with a stated rationale, visible in-app — autonomous decisions are never silent.

Tenant isolation

Every workspace-scoped query is filtered by workspace at the data-access layer — one customer's campaigns, leads, and sent-email history are never reachable from another's session.

Suppression

Any contact or domain added to a workspace's suppress list is checked before every send, so a suppressed contact can never be emailed again by that workspace.

See our Privacy Policy and Compliance FAQ for current status — both are explicit about what's still pending legal review rather than presenting draft text as finalized policy.