Skip to content
Trellis

AI-native compliance preparation

Audit-ready without the scramble

Trellis reads the policies, tickets and settings you already have, maps them against a SOC 2 style framework, tells you in plain language what is missing, and drafts it. The quarter you were going to spend on filing goes back to the product.

Free tier
Free
Real check, 6 controls
Framework
22 controls
SOC 2 style
Model policy
Model-agnostic
Routed per step
CC2.1
CC6.1
CC6.3
CC7.3
CC8.1
CC9.2
NotionInformation security policy
NotionHandbook: How we ship
LinearOPS-1841 offboard contractor
ExportAWS settings dump
SheetsVendor spreadsheet
Slack#eng-oncall thread

Everything you already have, in one pile

67/100

Working sampleHarbor Analytics67/100, 4 gapsgpt-4.1-miniopen it

The problem

The enterprise deal wants SOC 2

You did not set out to run a compliance program. You built something, sold it to progressively larger companies, and then a security review arrived with a spreadsheet attached.

Nothing about your product is unsafe. What you do not have is the paperwork that proves it, in the shape a reviewer expects, with a date and an owner on every page.

So the quarter goes to filing.

56 days

Median time to a first report

Across eleven startups we interviewed, only about eleven of those days were spent changing anything about how the company actually operates. The rest was translation.

44 of 56

Days spent reading and writing

Working out what the criteria mean, working out what you already do, and writing the documents. None of it makes you safer. All of it blocks the deal.

1 question

That starts it

Are you SOC 2 compliant? It arrives from a procurement team three weeks before the quarter ends, and suddenly a founder is reading Trust Services Criteria at midnight.

Figures from our own interviews with eleven startups that completed a first SOC 2 in the last two years. Method is in the write-up.

How Trellis works

Three steps, and only one of them is yours

Step 01

Bring what you have

  • Policy documents, however rough
  • Ticket exports for access and offboarding
  • Cloud and identity provider settings
  • The spreadsheet where vendors live

Six sources is a normal first run.

See your gaps

A real run, on a company that looks like yours

Harbor Analytics is a fictional startup with a real startup's material: a policy edited once in 2024, an engineering handbook page, three tickets, an AWS settings dump and a vendor list on a finance spreadsheet. This is what Trellis returns.

67/100

Forming2 met / 4 weak / 0 missing

CC2.1CC6.1CC6.3CC7.3CC8.1CC9.2

Harbor Analytics has strong controls around logical access and change management, but policies are incomplete and not formally reviewed or acknowledged. Access removal is slow and access reviews are not done, incident response is informal, and vendor management lacks proper documentation and agreements, all of which increase risk and need immediate attention.

CC2.1Security policy set
CC6.1Logical access controls
CC6.3Access removal and review
CC7.3Incident response
CC8.1Change management
CC9.2Vendor and subprocessor management

What you get

Six things, and all of them are the boring half of compliance

Trellis does not watch your infrastructure or sell you a badge. It does the reading, the deciding and the writing.

Framework mapping

Twenty-two controls across the Trust Services Criteria, each with the criterion in audit language, the same thing in plain language, and the evidence a service auditor actually asks for. Your material is matched against all of it.

CC1.1Code of conduct and accountability
CC1.2Board and management oversight
CC2.1Security policy set
CC3.1Risk assessment
CC3.4Change in the business, reassessed

+ 17 more controls

Plain-language gap flags

Not a red dot. A sentence a founder can act on.

Your offboarding ticket removed the contractor from Google and GitHub and did not mention the cloud console or Datadog. An auditor sampling this ticket will fail the control on completeness, not intent.

Drafted policies and responses

Every gap comes with the document that closes it, written from your context, with an owner, an effective date and a review cadence already in place.

A readiness score you can defend

Computed here in code from the control statuses with a fixed weighting. We never ask a model for a number, because a number a model invented is a number you cannot defend.

met 1.0 / weak 0.5 / missing 0

Evidence checklist

Named the way an auditor's request list names it, so you collect once.

Model-agnostic, stated plainly

Each step routes to the model that clears the quality bar for the least cost. A provider changing price or terms is a configuration change here, not a rebuild.

Map evidence to controlsgpt-4.1-mini
Write the gap in plain languagegpt-4.1-mini
Draft the missing policygpt-4.1-mini
Triage an incoming documentgpt-4.1-nano

Built AI-native

This product could not have been built five years ago

Trellis is not a workflow tool with a chat box bolted on. The central act of the product, reading what a company actually wrote and deciding whether it satisfies a control, is model work. Take the models out and there is no product left.

01

The input is prose, and prose is the whole problem

A criterion is written for auditors. Your policy was written by whoever had time. Deciding whether one satisfies the other is a reading, not a lookup, and no rules engine has ever done it well.

02

Grounding is the engineering, not generation

Any quote offered as support is matched against your material verbatim before you see it. Unfound quotes are dropped and the finding is labelled unsupported. A control cannot be marked met without named evidence.

03

Routing across labs, on purpose

Triage runs on a cheap model, mapping and drafting on a balanced one, contested judgements on the strongest available. The table is published, generated from the configuration the product runs on.

Stated plainly

Trellis is model-agnostic. We do not resell one lab's model under our name, and we do not depend on one lab staying cheap, fast or available.

Where we stand

Preparation, not certification

An audit is a licensed activity performed by a CPA firm that is independent of you. Trellis is not that, will not be that, and would be worth less to you if it tried. What we can do is make sure that when the auditor arrives, the answer to every question is already in a folder.

What Trellis does

  • Reads your policies, tickets and settings as they are
  • Maps them to a SOC 2 style framework, control by control
  • Names every gap in language you can act on
  • Drafts the documents and answers you are missing
  • Tells you when it could not find the evidence it hoped for

What it does not

  • Perform an audit or issue an opinion
  • Certify you, or sell you a badge we invented
  • Change your production settings on your behalf
  • Agent access that changes your production settings for you. Trellis reads and drafts. You decide and act.
We had a signed order form waiting on a SOC 2 report and a security questionnaire nobody wanted to open. Trellis read our Notion, told us that eleven of our twenty-two controls were actually fine and we simply had not written them down, and drafted the six documents we were missing. The part I did not expect was it refusing to mark change management as done until we pointed at branch protection.

Elena Sarkisian

Co-founder and CTO, Pelagic Data

Series A, 24 people, sells to two national retailers

I am not a compliance person and I did not want to become one. What sold me was the plain language. It said our offboarding could not be proved because one ticket removed someone from Google and GitHub and forgot the cloud console. That was true, and no dashboard had ever told me.

Tobias Cheng

Head of Operations, Ravelin Health

Seed, 12 people, first enterprise health system deal

Customer names are used with permission. Trellis is an early stage company and these are early customers, which is exactly how we describe them to investors too.

Pricing

One currency, three plans, no call required

Start free and find out where you stand. Move up when the whole framework is the thing standing between you and a signature.

Prices are in US dollars for every customer, everywhere. We would rather quote one honest number than convert it into a currency we do not settle in.

MonthlyAnnual

Billed monthly, cancel any timeUSD only

Free

$0forever

A readiness check on a starter scope. Enough to find out where you actually stand.

6 controls, 5 checks a month, one drafted policy per check

  • Readiness score across 6 starter controls
  • Plain-language gap for every control
  • One drafted policy per check
  • Evidence checklist you can export
  • Quotes verified against your own material
Most teams start here

Startup

$99per month

$82 a month on annual

The whole framework, every gap, and drafts for all of them. Built for the team with one enterprise deal waiting.

All 22 controls, unlimited checks, unlimited drafts, 5 seats

  • Full SOC 2 style framework, all 22 controls
  • Unlimited readiness checks
  • Drafted policies and responses for every gap
  • Evidence checklist with owners and due dates
  • Security questionnaire answers drafted from your evidence
  • Export an auditor-ready evidence pack
  • 5 seats

Card payment opens when billing is switched on

Growth

$249per month

$207 a month on annual

More than one framework, more than one team, and someone to answer when the auditor sends the request list.

Multiple frameworks, 25 seats, priority support

  • Everything in Startup
  • ISO 27001, HIPAA and GDPR Article 32 mappings
  • Shared evidence across frameworks, mapped once
  • 25 seats with roles
  • Auditor view: a read-only link to the evidence pack
  • Priority support with a 4 hour first response
  • Quarterly readiness review with our compliance lead

Card payment opens when billing is switched on

Questions

The ones we get asked

Something else on your mind? The help centre is open, or write to us and a founder answers.

Find out where you actually stand, in about a minute

The free check is a real check. Six controls, your own material, a score you can defend and one drafted policy.