PhotoTouch

Platform Security Summary

TriPrism, Inc. / PhotoTouch, Inc.

Document Date: April 28, 2026

This document summarizes the security controls and compliance posture of the PhotoTouch platform. It is intended for use by photographers and their enterprise clients (schools, venues, retailers, event organizers) who require vendor security documentation.

For the full security overview, visit admin.findyourpictures.com/legal/security. For detailed documentation, contact security@triprism.com.

1. Service Overview

ItemDescription
ServiceCloud-based photography business management platform (event management, file storage, customer communications, order processing, reporting)
DeploymentCloud-hosted — no on-premise installation required
Data Center LocationUnited States
Photo StorageLiquidWeb-hosted object storage (S3-compatible) with server-side encryption
Payment ProcessingDelegated to PCI Level 1 certified payment processors — no card data stored on platform
Status Pagestatus.triprism.com

2. Data Protection & Access Control

Encryption

Authentication

Authorization

3. Audit Logging & Monitoring

4. Incident Response

5. Backup & Recovery

6. Endpoint & Infrastructure Security

7. Data Privacy

8. Compliance Status

FrameworkStatus
SOC 2 Type IISOC 2-aligned controls implemented; formal Type II attestation in progress
GDPR (EU)Platform controls designed to support compliance (controller obligations remain with each photographer)
CCPA/CPRA (California)Platform controls designed to support compliance
COPPA (Children’s Privacy)Platform controls designed to support compliance; photographer remains responsible for consent workflows
CAN-SPAM / TCPAPlatform controls designed to support compliance
PCI DSSVia Certified Processors

Current Assurance Posture (As of April 28, 2026)

Periodic Review Schedule

Review TypeFrequency
Audit Log ReviewEvery 30 days
Audit Log + Access ReviewEvery 90 days
Credential Rotation ReviewEvery 180 days
Platform Integration AuditAnnually (365 days)

9. Legal Documentation

The following documents are publicly available:

DocumentURL
Privacy Policyadmin.findyourpictures.com/legal/privacy
Terms of Useadmin.findyourpictures.com/legal/terms
Data Processing Agreementadmin.findyourpictures.com/legal/dpa
Security Overviewadmin.findyourpictures.com/legal/security
Sub-Processor Disclosureadmin.findyourpictures.com/legal/subprocessors

10. Contact

PurposeContact
Security Inquiriessecurity@triprism.com
Vulnerability Disclosuresecurity@triprism.com
Platform Statusstatus.triprism.com