Built from the ground up with security in mind
Troopr protects your data with enterprise-grade security: SOC 2 Type II, ISO 27001, GDPR, and 99.9% uptime over 6+ years. Our founding team has decades of experience building enterprise integration systems with industry-leading security.
Free for 3 users. No credit card required. Runs in Slack.
Trusted by 600+ engineering teams worldwide
Independently audited, every year
Security is paramount at Troopr. Your data is protected with industry-leading measures and verified by third parties.
SOC 2 Type II
An independent third party conducts an annual SOC 2 Type II audit covering the Common Criteria plus the Confidentiality and Privacy trust services criteria. Report available to clients and prospects under NDA.
ISO 27001
Certified to ISO 27001 and maintained through annual third-party audits, governing how we manage information security across the company.
GDPR ready
We take data handling for EU customers seriously, are ready to meet data subject requests, and abide by the European Commission's standard contractual clauses.
PCI compliant
Troopr does not process PCI data and uses a third party for payments. We complete an annual Self Assessment Questionnaire (A-EP) and scan public-facing connections monthly.
DPA & data residency
A Data Processing Addendum with SCCs for international transfers, CCPA service-provider terms, and data residency on AWS in US or EU regions per your configuration.
Encrypted end to end
TLS 1.2 in transit and AES-256 at rest across databases, file stores, and backups, with keys managed by AWS KMS and rotated annually.
Always on, by design
With proven uptime over 6+ years, you can be confident Troopr is there when your team needs it.
99.9%
Uptime over 6+ years
Production-grade monitoring since Troopr Labs began in 2019.
AWS
Resilient infrastructure
Hosted on AWS data centers with EC2 Auto Scaling that provisions capacity ahead of demand.
Daily
Encrypted backups
Off-site on Amazon S3, with regular restore tests and defined RTO and RPO.
Annual
BIA & BCP reviews
Business Impact Analysis and Business Continuity Plan reviewed every year.
"We picked Troopr because it was cleared by our internal security team and the Jira integration just worked. Troopr boasts stable development and a responsive support team."
Engineering, Netflix · async standups via Check-ins
AI that stays in its lane, and asks before it acts
Troopr's AI drafts and proposes; people decide. It is scoped to specific tasks, confirms before it changes anything, and never trains on your data.
Confirms before it acts
Every proposed Jira change is confirmed by the person in a direct message before Troopr makes it. Nothing is changed silently or in public on someone's behalf.
No training, never sold
Troopr never uses your data to train models, and never sells personal information. Your prompts and content are not used to improve any model beyond serving your own team.
Derived facts, not raw messages
Troopr persists a structured set of facts about how your team works, visible and correctable by your team. Live standup transcripts are kept 30 days, then deleted. The raw firehose is never hoarded.
Reads only what it should
Troopr reads team channels, connected work tools, and a person's own shared activity, always within your Jira permissions. It does not read other people's private direct messages.
Scoped to specific tasks
AI is used for named jobs: creating an issue from a thread, drafting a standup, and summarizing check-ins. It is not an open-ended agent acting on its own.
Grounded in your real work
Drafts and proposals are built from your actual Jira, GitHub, and Slack activity, your own edits, and meeting notes, so output reflects what really happened.
The details security teams ask about
Troopr sits between Jira and Slack and does not hoard the raw content of your messages. It derives and persists a structured set of facts about how your team works, the information it needs to draft updates and keep Jira current, and nothing more.
Troopr's access to issues and fields is controlled by your Jira permissions and never bypasses them, so you always control access. Authentication uses OAuth and documented public REST APIs.
Yes. Troopr supports single sign-on for a seamless login experience, so there is no separate account or password to manage. Administrators can also assign roles using role-based access control on the principle of least privilege.
Yes. Administrators set roles with role-based access control so people see only what they need, and Troopr keeps audit logs of access and administrative actions, available to customers for security and compliance review.
All communication uses TLS 1.2 / HTTPS. All stored data is encrypted at rest with AES-256, including relational databases, file stores, and backups. Keys are generated and managed by AWS KMS and rotated once a year.
Troopr is hosted in AWS data centers. The hosting environment maintains ISO 27001, FedRAMP authorization, PCI certification, and SOC reports, and AWS restricts physical access to authorized personnel.
For organizations still on Jira Data Center, Troopr's Enterprise self-hosted deployment runs as a Docker image inside your network and can connect to a Data Center instance, so your team keeps working as you migrate to Jira Cloud. Atlassian is ending Data Center support on March 28, 2029, with expansions for existing Data Center customers until March 30, 2028, so this is best treated as a bridge through that move. It is configured as part of an Enterprise agreement; reach our team at security@troopr.io or through the demo page.
Customer data is stored in multi-tenant datastores and assigned a unique tenant token, which prevents one customer from accessing another customer's data.
Production access is limited to a small group and granted only through signed permission, with a documented quarterly account review. Personnel with access must agree to confidentiality terms, pass a background screening, and complete security training. All access is removed immediately on termination.
Any vendor that could access sensitive client data must provide an external audit or, at minimum, complete a risk interview and demonstrate best practices. These are refreshed annually, and every vendor signs a Data Processing Agreement.
Troopr scans its systems regularly and patches automatically, prioritizing critical and high-severity fixes. An in-app security platform detects and blocks attacks, helping prevent data breaches, account takeovers, and business logic attacks.
Yes. Troopr partners with external penetration testing vendors for annual tests. Medium and higher severity findings are remediated, with reports available under NDA.
Backups run daily, encrypted in transit and at rest, with regular tests, stored off-site on Amazon S3. Troopr reviews its Business Impact Analysis and Business Continuity Plan annually and maintains defined Recovery Time and Recovery Point Objectives. Reports available under NDA.
Troopr maintains and verifies its incident response policy, rehearsing potential incidents twice a year. Any confirmed data breach would be communicated to a client's Troopr administrator within 24 hours.
Security is built into development. OWASP Top 10 risk classification validates new code before deployment, all code is version-controlled with peer review and continuous integration testing, and developers complete specialized security training.
An independent firm conducts an annual SOC 2 Type II audit covering the Common Criteria plus Confidentiality and Privacy. Troopr also runs quarterly internal audits, with well-defined, documented roles for data protection.
Yes. Troopr runs an active bug bounty program with ethical hackers, evaluating and remediating submissions by severity. Report a vulnerability to security@troopr.io.
Clear terms, current sub-processors
Our Data Processing Addendum covers Standard Contractual Clauses for international transfers, CCPA service-provider terms, and a 30-day notice before any new sub-processor.
AI providers, API-only
AI features use API access to providers like OpenAI, Anthropic, and Azure OpenAI under agreements that prohibit using your data for model training. Providers do not retain prompts or responses beyond processing each request.
Data residency and deletion
Hosted on AWS with data residency in US or EU regions per your configuration. On termination, your data is available to export for 30 days, then deleted within 90 days.
The documents
Read the full DPA, sub-processor list, privacy policy, and terms of service. Audit reports are available to customers under NDA.
Security your team can build on
SOC 2 Type II, ISO 27001, and GDPR, with the deployment options enterprise engineering needs. Talk to us, or start free today.