Skip to main content
All data elements obtained from devices (phones and computers) are visible only to the tenant administrators for the organization. TruU does not have visibility into the data captured from user devices. The sections below describe what data is captured and stored in the TruU Identity Platform.
Last reviewed: September 2026. This page reflects the TruU cloud platform as currently deployed. Where a data element is optional or depends on a feature the organization has enabled, this is noted.

Phones

Mobile authenticators (the TruU app or an app embedding the TruU SDK). The same record type is used for Windows and Mac built-in authenticators, third-party FIDO2 security keys, and passkeys.
  • Device Name — Name the user has chosen for their device.
  • Device ID — A unique alphanumeric string generated by TruU to identify a device.
  • Device Type — iOS, Android, Windows (TPM), Mac (Secure Enclave), third-party FIDO2 security key, or passkey.
  • Operating System Version — The operating system version reported by the device.
  • Notification ID — The push-notification token; captured only if the user has enabled notifications.
  • App Version — The version of the TruU app.
  • SDK Version — The version of the TruU SDK.
  • App Identifier — The bundle identifier of the app that contains the TruU SDK.
  • Hardware Identifier — An identifier of the device hardware or authenticator model.
  • Language — The language the device is configured with, used for notifications and messages.
  • Domain ID — The TruU tenant the device is registered to.
  • TUID — An alphanumeric string that uniquely identifies the owning user to TruU.
  • Status — Whether the device is active, when it was enrolled, and when and why it was removed.
  • Last Heard From — The last time the device checked in with TruU.
  • Last Authentication — The time and outcome of the most recent authentication performed with the device.
  • PIN Change Timestamps — When the device PIN was last changed and whether an administrator has requested a PIN change. The PIN itself is never stored (see Authenticators and Credentials).
  • Assurance Level — The assurance level assigned to the device at enrollment.
  • Device Capabilities — Which authentication capabilities the device supports, for example biometric unlock or FIDO2.
  • Continuous Authentication Model Status — Whether a behavioral model has been trained for the device; only when continuous authentication is enabled.
  • Proximity Identifier — A rotating identifier the device broadcasts for workstation proximity unlock.
  • Administrator Requests — Pending administrator requests for the device to upload diagnostic logs or renew its certificate.

Workstations

Windows and Mac computers running the TruU agent, and Linux servers running the TruU PAM module.
  • Device Type — Windows agent, Mac agent, or PAM module.
  • Device Name — Computer name and display name.
  • Asset ID — A unique identifier generated by TruU for the computer.
  • Directory GUID — The computer’s unique identifier in the enterprise directory, when it is domain-joined.
  • Operating System — Operating system name and version.
  • TruU Agent Version — Version of the TruU agent installed.
  • Hardware — Serial number, manufacturer, model, processor, BIOS version, and whether secure hardware storage (TPM or Secure Enclave) is present.
  • Network — IP and MAC addresses of the computer’s network interfaces.
  • Last Signed-in User — The user principal name of the user who last signed in with TruU.
  • Shared Workstation — Whether the computer is configured as a shared workstation.
  • Status — Whether the computer is active, when it was enrolled, when it last checked in, its last authentication, and when and why it was removed.
  • Trust Keys — The agent’s public key and a TruU-held key pair used to establish trust with the agent; the private key is stored encrypted.
  • Software Installation Status — Status of TruU-initiated agent installations and updates.
  • Administrator Requests — Pending administrator requests for diagnostic logs.

Users

TruU uses information and status from the enterprise’s directory (Active Directory, Microsoft Entra ID, Okta, Oracle Identity Cloud, Google Cloud Directory, or a customer REST directory). The following data elements are captured for a user during the enrollment / registration process and are refreshed when the user authenticates or the directory record changes. Additional directory attributes are read only when needed, for example to send an enrollment invitation, and are not kept as part of the user record.
  • GUID — The user’s unique identifier within the directory. The previous identifier is kept after a directory migration.
  • DisplayName — The user’s display name in the source directory.
  • UserPrincipalName — The primary user principal name from the source directory.
  • Email (optional) — Email address of the user from the source directory, used during the enrollment workflow and for notifications.
  • Login Identifier — The value of the directory attribute the organization has chosen for single sign-on login.
  • TUID — An alphanumeric string that uniquely identifies the user to TruU.
  • Source Directory — Which of the organization’s configured directories the user was synchronized from.
  • Activity Timestamps — Last login and last access per channel (single sign-on, workstation, server, web application, physical access, shared workstation), and last directory synchronization.
  • Risk Score — A user risk score (0–100), when it last changed, and administrator pin/verify flags; only when the risk feature is enabled.
  • Continuous Authentication Model Status — Whether a behavioral model has been trained for the user; only when continuous authentication is enabled.
  • Configured Directory Attributes — The list of directory attributes the organization has chosen to make available to TruU (for example phone numbers, department, manager, photo) and how they are mapped.
  • Enrollment Invitations — Email address, phone number, display name, one-time enrollment code, expiry, the administrator who issued the invitation, and for manager-assisted enrollment the manager’s contact details.
  • Enrollment Verification — When enrollment requires approval, the approvers and their decision.
  • Entitlements — Application and workstation entitlements assigned to the user.

Groups

TruU can be configured to synchronize directory groups from the enterprise directory. These groups can be used to configure and define policies within the admin console. The customer has complete control over which groups are synchronized. Group membership is evaluated against the directory when needed and is not stored by TruU.
  • GUID — Group unique identifier within the directory.
  • Name — The name of the group.
  • Type — The type of the group (Universal, Global, Domain Local) — used for AD installations.
  • DistinguishedName — The distinguished name of the group — used only for LDAP directories.
  • Account Name and Security Identifier — The group’s account name (sAMAccountName) and SID — used for AD installations.
  • Status — Whether the group is still present in the directory.
  • Policy Links — Which TruU policies reference the group.

Authenticators and Credentials

  • FIDO2 / Passkey Credentials — For each enrolled authenticator: the credential identifier, the credential’s public key, the authenticator type and model identifier (AAGUID), whether it is a resident key (passkey), and the device it belongs to. Private keys never leave the authenticator.
  • Synced Passkeys — For organizations using Microsoft Entra ID synced passkeys, a sealed key blob stored on the user’s behalf. TruU cannot read its contents.
  • PIN — The user’s PIN is never stored. TruU stores only a salted one-way hash used to verify it, together with the PIN policy that applies.
  • Badges — For physical-access badges assigned to a user: badge nickname, card number, facility code, card serial number, card format, and protocol.
  • Enrollment Codes — Short-lived one-time enrollment codes and tokens, removed after they expire.
  • Integration Credentials — Identifiers of TruU agents and API integrations; their secrets are stored only as one-way hashes.

Biometric Data (TruFace)

Captured only when the organization enables the TruFace factor. Fingerprint and face unlock on phones and computers use the device’s own biometric hardware; no fingerprint or device-biometric data is ever sent to TruU.
  • Face Reference Image — One reference face image per enrolled user, stored encrypted.
  • Face Template — A mathematical representation of the face, which cannot be converted back into an image, held in a face-recognition collection dedicated to the organization. It is created only when the organization’s face configuration permits storing biometric data.
  • Storage Location — TruU’s cloud account by default. The organization may instead configure its own AWS account and region, in which case both the image and the template are stored there and TruU accesses them only through a role the organization grants.
  • Liveness Checks — Liveness verification runs in the user’s browser or app. TruU keeps only the resulting reference image, not the video.
  • Biometric Consent — Consent status (granted or revoked), the consent policy version and document, the date, the device used, and the IP address and approximate location of the consenting client.
  • Retention — The image and template are deleted when the user removes the factor, an administrator deletes it, consent is revoked or expires, or the organization is off-boarded.
  • External Photo Sources — If the organization supplies enrollment photos from its own storage, the connection settings are stored encrypted and photos are read at enrollment only.

Certificates and Keys

  • Organization Certificates — Certificates and keys used for single sign-on (SAML/OIDC), identity-server TLS, token signing, and client-certificate trust: name, type, validity period, state, and associated host name. Private keys are stored encrypted.
  • Device Certificates — For certificate-based (virtual smart card) logon: the certificate identifier, validity period, and issuing certificate-authority path. The certificate and its private key remain on the user’s device.
  • Signing Keys — Key pairs used by TruU services to sign tokens, rotated automatically. Only public keys are shared with relying services.

Authentication and Audit Events

TruU records events for authentication, enrollment, device activity, policy decisions, continuous authentication, and administrator actions so that administrators can search, export, and route them, for example to a SIEM. Depending on the event type, an event may contain:
  • Event — Type, time, outcome (success or failure), message, and error code.
  • Actor — User principal name, display name, directory GUID, TUID, and email; and when the organization has configured them, title, department, and manager.
  • Client — IP address, approximate geolocation derived from it, browser or user agent, and request details.
  • Device or Workstation — Device identifier and name, app and SDK version, operating system, hardware summary, network interfaces (IP and MAC addresses), assurance level, and language.
  • Factors — Which authentication factors were used and their assurance level.
  • Policy and Workflow — Which policy and workflow applied, their version, and the decision.
  • Target — The application, workstation, server, or resource that was accessed.
  • Continuous Authentication — Score and level, when enabled.
  • Administrator Audit Log — Every administrator action in the admin console: who, what, when, outcome, and details.
  • Administrator Sessions — Session start, expiry, and login method.
  • Diagnostic Logs — When requested by an administrator, TruU app or agent diagnostic log archives uploaded from a device, tagged with user and device.
  • Message Delivery Status — Delivery status of enrollment and notification emails and text messages: recipient, subject, and status.
  • Retention — Events are kept for the retention period configured for the organization. Exports generated by administrators are kept in a TruU export location and made available through time-limited links.

Policies and Tenant Configuration

  • Tenant — Organization name, domain, short code, settings, and licensed features.
  • Policies — Authentication, registration, privacy, physical access, computer, server, shared workstation, human risk, and update policies, with full version history and the administrator who edited each version.
  • PIN Profiles — PIN complexity and lifetime rules.
  • Trusted Networks — Named IP address ranges.
  • Directory Connections — Connector type, endpoints, search bases, and the service-account identity used to read the directory. Service-account passwords, client secrets, and API tokens are stored encrypted with a key dedicated to the organization.
  • Integrations — Single sign-on, PKI, physical-access, RADIUS, event-logging, and other connectors: name, type, endpoint, and configuration. Credentials are stored encrypted.
  • Identity Servers — For organizations running TruU identity servers: host name, version, health, IP address, and certificates.
  • Alerts — Alert configuration (recipient email addresses, webhooks) and current alerts.
  • Physical Access — Buildings (name, location, and radius used for geofencing), readers and reader groups (names and identifiers; transport keys stored encrypted), access levels, card formats, and cardholder assignments.
  • Attribute Mapping — How directory attributes map to TruU attributes and any transformations applied.
  • Branding and Messaging — Customized portal text, email and text-message templates, and translations.
  • Administrators — Administrator accounts: user name, name, email, role, and login method. Passwords and one-time codes are stored only as hashes.

Transient and Cached Data

  • Short-lived data is held in in-memory caches with automatic expiry: authentication sessions and challenges, one-time codes, PIN-attempt counters, cached directory lookups (minutes), face-match results (minutes), and service signing keys. This data is purged automatically and is not a long-term record.

Storage and Data Transmission

Data from the device is securely transferred and stored in the TruU Identity Platform:
  • All data in motion is secured with TLS 1.2 or greater; TLS 1.3 is preferred at all public endpoints. HTTP Strict Transport Security is enforced.
  • Traffic between TruU services and their databases, caches, search indices, and message bus is encrypted with TLS, and services authenticate to each other with scoped OAuth 2.0 tokens.
  • All data at rest is secured with AES-256-bit encryption using AWS Key Management Service keys managed by TruU (databases, search indices, message bus, caches, and object storage).
  • Secrets such as directory service-account passwords, connector credentials, and private keys are additionally encrypted with a key dedicated to the organization before they are stored. Platform secrets are held in AWS Secrets Manager.
  • PINs and integration secrets are stored only as salted one-way hashes and cannot be recovered.
  • Face images and templates are stored encrypted and may optionally be stored in the organization’s own AWS account and region.
  • The platform is hosted in AWS US West (Oregon); encrypted backups and snapshots are replicated to AWS US East for disaster recovery.
  • Removing a user, device, or workstation marks the record deleted and removes dependent data. Devices that stop checking in are removed automatically according to the organization’s security settings, enrollment codes and invitations expire, biometric data is deleted as described above, events are retained for the organization’s configured retention period, and when an organization is off-boarded its records and biometric collections are removed.