<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://trufend.com/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://trufend.com/product/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://trufend.com/guide/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://trufend.com/blog/</loc>
    <lastmod>2026-09-17</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/blog/api-key-rotation.html</loc>
    <lastmod>2026-07-15</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-api-key-rotation.jpg</image:loc>
      <image:title>Rotating API keys on a schedule, not after an incident</image:title>
      <image:caption>API key rotation illustration: a weekly calendar with keys cycling through scheduled renewal, automated deployment of a new key, and automatic expiry of the old one, labelled to show rotation as a routine rather than an incident response.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/api-key-scope.html</loc>
    <lastmod>2026-06-03</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-api-key-scope.jpg</image:loc>
      <image:title>Scoping service-role and admin API keys</image:title>
      <image:caption>API key scope illustration: a narrowly scoped service-role key with limited access to specific resources beside an admin key with full access to every resource, the admin key ringed by a visibly larger blast radius, above an application connected to its database, services and APIs.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/backup-restore-testing.html</loc>
    <lastmod>2026-06-10</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-backup-restore-testing.jpg</image:loc>
      <image:title>Backups mean nothing until you restore one</image:title>
      <image:caption>Restore testing illustration: data crossing a bridge from backup storage through a restore test that validates and verifies integrity, arriving at a restored and ready application with its data recovered.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/branch-protection.html</loc>
    <lastmod>2026-07-22</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-branch-protection.jpg</image:loc>
      <image:title>Branch protection: stopping direct pushes to main</image:title>
      <image:caption>Branch protection illustration: feature and bugfix branches climbing to a pull request, through required code review and passing checks, before merging into a protected main branch that refuses direct pushes.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/data-processing-agreements.html</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-data-processing-agreements.jpg</image:loc>
      <image:title>Data processing agreements: which ones you need</image:title>
      <image:caption>Data processing agreement illustration: a signed DPA bridging a company acting as controller and a vendor acting as processor, listing the clauses it should cover including purpose and scope, types of personal data, security measures, sub-processors, data subject rights, and retention and deletion.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/enforcing-mfa.html</loc>
    <lastmod>2026-07-01</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-enforcing-mfa.jpg</image:loc>
      <image:title>Requiring MFA, not just offering it</image:title>
      <image:caption>Multi-factor authentication illustration: a sign-in screen above a gate marked secure access only, requiring a second factor by phone approval or security key, labelled to show MFA as mandatory rather than optional.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/exposed-secrets.html</loc>
    <lastmod>2026-04-15</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-exposed-api-keys-public-code-security.jpg</image:loc>
      <image:title>Exposed secrets: how API keys end up in public code</image:title>
      <image:caption>Exposed secrets illustration: a laptop showing a public code repository with a live API key highlighted on one line of a config file, and a scan panel reporting three secrets found, the API key rated high risk.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/external-security-posture.html</loc>
    <lastmod>2026-05-13</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-external-security-posture-domain-scan.jpg</image:loc>
      <image:title>External security posture: what anyone can see from outside your domain</image:title>
      <image:caption>External security posture illustration: a browser window showing a company domain, with callouts for DNS records, public subdomains, TLS certificate and protocol versions, exposed assets such as APIs and admin panels, and HTTP security headers.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/free-server-log-analyser.html</loc>
    <lastmod>2026-09-17</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-free-server-log-analyser.jpg</image:loc>
      <image:title>A free server log analyser that never uploads your log</image:title>
      <image:caption>Free server log analyser: a log window above a mountain range at dawn, showing access log lines with timestamps, 200 and 404 status codes and requested paths beside the user agent strings of Googlebot, Bingbot, AhrefsBot, ClaudeBot, GPTBot, SemrushBot, PerplexityBot and Applebot, with each crawler&#x27;s route traced across the peaks below and a note that the log is read locally in the browser.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/graceful-degradation.html</loc>
    <lastmod>2026-06-24</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-graceful-degradation.jpg</image:loc>
      <image:title>When a dependency goes down, does your app break?</image:title>
      <image:caption>Graceful degradation illustration: an application on a mountain peak still online and serving users while one third-party API is marked unavailable and the payments, analytics and email services around it stay healthy, one of them on a fallback route.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/idor-testing.html</loc>
    <lastmod>2026-05-27</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-idor-testing.jpg</image:loc>
      <image:title>IDOR: can your customers see each other&#x27;s data?</image:title>
      <image:caption>IDOR illustration: two customer accounts on opposite cliff tops, each holding its own profiles, orders, invoices and support tickets, with a request to another customer&#x27;s record ID crossing between them and flagged as unauthorised access.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/incident-response-plan-contents.html</loc>
    <lastmod>2026-08-12</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-incident-response-plan-contents.jpg</image:loc>
      <image:title>What belongs in a written incident response plan</image:title>
      <image:caption>Incident response plan illustration: a path from detection through containment, investigation and recovery, with panels describing the roles involved, the communications required, and the evidence to preserve at each stage.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/not-a-certification.html</loc>
    <lastmod>2026-04-01</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-domain-scan-not-soc-2-certificate.jpg</image:loc>
      <image:title>Why we&#x27;ll never call this a SOC 2 certificate</image:title>
      <image:caption>Domain scan versus SOC 2 illustration: a small panel of passing external checks for TLS, certificate validity, open ports and known vulnerabilities, set against a far larger landscape labelled with the internal areas SOC 2 covers, including people and access, processes and policies, data protection, incident response, vendor management and risk governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/offboarding-checklist.html</loc>
    <lastmod>2026-07-08</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-offboarding-checklist.jpg</image:loc>
      <image:title>The offboarding checklist that actually revokes access</image:title>
      <image:caption>Offboarding illustration: a checklist covering revoking access, disabling accounts, removing group membership, transferring ownership and confirming, connected to a departing employee whose access is removed across Google Workspace, Microsoft 365, Slack, GitHub, Salesforce and other applications.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/reading-your-report.html</loc>
    <lastmod>2026-03-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-external-security-report-guide.jpg</image:loc>
      <image:title>How to read your Trufend report</image:title>
      <image:caption>Trufend report illustration: a laptop showing a scan result for a domain with an overall grade, a list of security checks marked pass, issue or warning across TLS, DNS, subdomains, headers and infrastructure, and a readiness checklist of next steps alongside it.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/risk-assessment.html</loc>
    <lastmod>2026-08-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-risk-assessment.jpg</image:loc>
      <image:title>Documenting a risk assessment in an afternoon</image:title>
      <image:caption>Risk assessment illustration: a likelihood and impact matrix beside a list of treatment options covering mitigate, transfer, accept and avoid, with example risks including a data breach, a supplier outage, a service disruption and a regulatory change plotted by their likelihood and impact.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/rto-and-rpo.html</loc>
    <lastmod>2026-06-17</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-rto-and-rpo.jpg</image:loc>
      <image:title>RTO and RPO: writing numbers you can actually defend</image:title>
      <image:caption>RTO and RPO illustration: a timeline along a mountain ridge from an outage, through the data loss window that the recovery point objective measures, to the restore time that the recovery time objective measures, ending at systems restored.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/secrets-out-of-git.html</loc>
    <lastmod>2026-07-29</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-secrets-out-of-git.jpg</image:loc>
      <image:title>Keeping secrets out of your Git repository</image:title>
      <image:caption>Secrets in source control illustration: a code editor showing a live API key highlighted in a config file, with pre-commit checks stopping secrets before they reach the repository, secret scanning detecting keys and tokens, and the credentials moving into a secure vault.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/security-headers.html</loc>
    <lastmod>2026-04-08</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-http-security-headers-website-protection.jpg</image:loc>
      <image:title>The security headers that actually matter</image:title>
      <image:caption>HTTP security headers illustration: layered translucent panels in front of a browser window, each labelled with a header and what it does, covering Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/security-training.html</loc>
    <lastmod>2026-08-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-security-training.jpg</image:loc>
      <image:title>Security training for new hires and contractors</image:title>
      <image:caption>Security training illustration: new joiners walking a path marked with the topics onboarding should cover, including phishing awareness, access basics such as accounts and least privilege, device handling, and how to report a problem, beside a welcome checklist.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/spf-dkim-dmarc.html</loc>
    <lastmod>2026-05-06</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-spf-dkim-dmarc-email-authentication.jpg</image:loc>
      <image:title>SPF, DKIM and DMARC: stopping people sending email as you</image:title>
      <image:caption>SPF, DKIM and DMARC illustration: a legitimate email crossing a bridge through three authentication gates that ask whether the sender is authorised, whether the message was tampered with, and what to do on failure, while a spoofed message fails and is blocked before the recipient inbox.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/subdomain-takeover.html</loc>
    <lastmod>2026-04-29</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-subdomain-takeover-dangling-dns-record.jpg</image:loc>
      <image:title>Subdomain takeover: the DNS record that outlived the service</image:title>
      <image:caption>Subdomain takeover illustration: a bridge that ends in mid-air at a cliff edge beside a sign reading service gone, labelled with a subdomain whose DNS record still points at a service that no longer exists.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/supabase-row-level-security.html</loc>
    <lastmod>2026-05-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-supabase-row-level-security.jpg</image:loc>
      <image:title>Row-Level Security: turning it on and checking it</image:title>
      <image:caption>Row-Level Security illustration: a database table of orders where some rows are visible and others are locked and greyed out, labelled to show that each user sees only the rows their policy allows and that rows failing the policy stay hidden.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/the-invisible-80.html</loc>
    <lastmod>2026-03-25</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-soc-2-invisible-80-domain-scan.jpg</image:loc>
      <image:title>The 80% a domain scan can&#x27;t see</image:title>
      <image:caption>Iceberg illustration: the fifth above the waterline is labelled with what scanners can see, including TLS and certificates, security headers, DNS records, public subdomains and exposed assets, while the far larger mass below is labelled with people and permissions, internal processes, access controls, backups and recovery, incident response and vendor management.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/tls-certificate-checks.html</loc>
    <lastmod>2026-04-22</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-tls-certificate-expiry-configuration-check.jpg</image:loc>
      <image:title>Expiring and weak TLS: what breaks, and what to check</image:title>
      <image:caption>TLS certificate illustration: a mountain path marked with three waypoints for checking your configuration, disabling old protocols such as SSL and TLS 1.0 and 1.1, and renewing on time, above a panel showing a valid certificate with its issue and expiry dates.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/vendor-inventory.html</loc>
    <lastmod>2026-09-02</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-vendor-inventory.jpg</image:loc>
      <image:title>Listing every vendor that touches your data</image:title>
      <image:caption>Vendor inventory illustration: a company application at the centre of a map of the external services that touch its data, including infrastructure, source control, collaboration, productivity, CRM, analytics, monitoring, payments and communications, with a count of vendors discovered and data categories.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/vendor-security-review.html</loc>
    <lastmod>2026-09-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-vendor-security-review.jpg</image:loc>
      <image:title>Reviewing a vendor&#x27;s security posture without a team</image:title>
      <image:caption>Vendor security review illustration: three vendor cards showing what evidence each has provided across TLS, security headers, access controls, a SOC 2 report, subprocessors and vulnerability management, two rated low risk and one still needing review, beside a short review checklist.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/blog/webhook-signature-verification.html</loc>
    <lastmod>2026-08-05</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <image:image>
      <image:loc>https://trufend.com/blog/images/trufend-webhook-signature-verification.jpg</image:loc>
      <image:title>Verifying webhook signatures from Stripe and others</image:title>
      <image:caption>Webhook signature illustration: signed events crossing a bridge into an application after their signature is verified, while an event with an invalid signature is rejected and blocked before reaching the app.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://trufend.com/privacy/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://trufend.com/terms/</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/csp-builder.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/incident-response-plan.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/log-file-analyser.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/security-headers-generator.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/spf-dmarc-generator.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://trufend.com/tools/vendor-dpa-register.html</loc>
    <lastmod>2026-09-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
</urlset>
