AI-native compliance preparation
Audit-ready without the scramble
Trellis reads the policies, tickets and settings you already have, maps them against a SOC 2 style framework, tells you in plain language what is missing, and drafts it. The quarter you were going to spend on filing goes back to the product.
- Free tier
- Free
- Real check, 6 controls
- Framework
- 22 controls
- SOC 2 style
- Model policy
- Model-agnostic
- Routed per step
Everything you already have, in one pile
67/100Working sampleHarbor Analytics67/100, 4 gapsgpt-4.1-miniopen it
The problem
The enterprise deal wants SOC 2
You did not set out to run a compliance program. You built something, sold it to progressively larger companies, and then a security review arrived with a spreadsheet attached.
Nothing about your product is unsafe. What you do not have is the paperwork that proves it, in the shape a reviewer expects, with a date and an owner on every page.
So the quarter goes to filing.
56 days
Median time to a first report
Across eleven startups we interviewed, only about eleven of those days were spent changing anything about how the company actually operates. The rest was translation.
44 of 56
Days spent reading and writing
Working out what the criteria mean, working out what you already do, and writing the documents. None of it makes you safer. All of it blocks the deal.
1 question
That starts it
Are you SOC 2 compliant? It arrives from a procurement team three weeks before the quarter ends, and suddenly a founder is reading Trust Services Criteria at midnight.
Figures from our own interviews with eleven startups that completed a first SOC 2 in the last two years. Method is in the write-up.
How Trellis works
Three steps, and only one of them is yours
Step 01
Bring what you have
- Policy documents, however rough
- Ticket exports for access and offboarding
- Cloud and identity provider settings
- The spreadsheet where vendors live
Six sources is a normal first run.
See your gaps
A real run, on a company that looks like yours
Harbor Analytics is a fictional startup with a real startup's material: a policy edited once in 2024, an engineering handbook page, three tickets, an AWS settings dump and a vendor list on a finance spreadsheet. This is what Trellis returns.
Forming2 met / 4 weak / 0 missing
Harbor Analytics has strong controls around logical access and change management, but policies are incomplete and not formally reviewed or acknowledged. Access removal is slow and access reviews are not done, incident response is informal, and vendor management lacks proper documentation and agreements, all of which increase risk and need immediate attention.
What you get
Six things, and all of them are the boring half of compliance
Framework mapping
Twenty-two controls across the Trust Services Criteria, each with the criterion in audit language, the same thing in plain language, and the evidence a service auditor actually asks for. Your material is matched against all of it.
+ 17 more controls
Plain-language gap flags
Not a red dot. A sentence a founder can act on.
Your offboarding ticket removed the contractor from Google and GitHub and did not mention the cloud console or Datadog. An auditor sampling this ticket will fail the control on completeness, not intent.
Drafted policies and responses
Every gap comes with the document that closes it, written from your context, with an owner, an effective date and a review cadence already in place.
A readiness score you can defend
Computed here in code from the control statuses with a fixed weighting. We never ask a model for a number, because a number a model invented is a number you cannot defend.
met 1.0 / weak 0.5 / missing 0
Evidence checklist
Named the way an auditor's request list names it, so you collect once.
Model-agnostic, stated plainly
Each step routes to the model that clears the quality bar for the least cost. A provider changing price or terms is a configuration change here, not a rebuild.
Built AI-native
This product could not have been built five years ago
Trellis is not a workflow tool with a chat box bolted on. The central act of the product, reading what a company actually wrote and deciding whether it satisfies a control, is model work. Take the models out and there is no product left.
The input is prose, and prose is the whole problem
A criterion is written for auditors. Your policy was written by whoever had time. Deciding whether one satisfies the other is a reading, not a lookup, and no rules engine has ever done it well.
Grounding is the engineering, not generation
Any quote offered as support is matched against your material verbatim before you see it. Unfound quotes are dropped and the finding is labelled unsupported. A control cannot be marked met without named evidence.
Routing across labs, on purpose
Triage runs on a cheap model, mapping and drafting on a balanced one, contested judgements on the strongest available. The table is published, generated from the configuration the product runs on.
Stated plainly
Trellis is model-agnostic. We do not resell one lab's model under our name, and we do not depend on one lab staying cheap, fast or available.
Where we stand
Preparation, not certification
An audit is a licensed activity performed by a CPA firm that is independent of you. Trellis is not that, will not be that, and would be worth less to you if it tried. What we can do is make sure that when the auditor arrives, the answer to every question is already in a folder.
What Trellis does
- Reads your policies, tickets and settings as they are
- Maps them to a SOC 2 style framework, control by control
- Names every gap in language you can act on
- Drafts the documents and answers you are missing
- Tells you when it could not find the evidence it hoped for
What it does not
- Perform an audit or issue an opinion
- Certify you, or sell you a badge we invented
- Change your production settings on your behalf
- Agent access that changes your production settings for you. Trellis reads and drafts. You decide and act.
We had a signed order form waiting on a SOC 2 report and a security questionnaire nobody wanted to open. Trellis read our Notion, told us that eleven of our twenty-two controls were actually fine and we simply had not written them down, and drafted the six documents we were missing. The part I did not expect was it refusing to mark change management as done until we pointed at branch protection.
Elena Sarkisian
Co-founder and CTO, Pelagic Data
Series A, 24 people, sells to two national retailers
I am not a compliance person and I did not want to become one. What sold me was the plain language. It said our offboarding could not be proved because one ticket removed someone from Google and GitHub and forgot the cloud console. That was true, and no dashboard had ever told me.
Tobias Cheng
Head of Operations, Ravelin Health
Seed, 12 people, first enterprise health system deal
Customer names are used with permission. Trellis is an early stage company and these are early customers, which is exactly how we describe them to investors too.
Pricing
One currency, three plans, no call required
Prices are in US dollars for every customer, everywhere. We would rather quote one honest number than convert it into a currency we do not settle in.
Billed monthly, cancel any timeUSD only
Free
A readiness check on a starter scope. Enough to find out where you actually stand.
6 controls, 5 checks a month, one drafted policy per check
- Readiness score across 6 starter controls
- Plain-language gap for every control
- One drafted policy per check
- Evidence checklist you can export
- Quotes verified against your own material
Startup
$82 a month on annual
The whole framework, every gap, and drafts for all of them. Built for the team with one enterprise deal waiting.
All 22 controls, unlimited checks, unlimited drafts, 5 seats
- Full SOC 2 style framework, all 22 controls
- Unlimited readiness checks
- Drafted policies and responses for every gap
- Evidence checklist with owners and due dates
- Security questionnaire answers drafted from your evidence
- Export an auditor-ready evidence pack
- 5 seats
Card payment opens when billing is switched on
Growth
$207 a month on annual
More than one framework, more than one team, and someone to answer when the auditor sends the request list.
Multiple frameworks, 25 seats, priority support
- Everything in Startup
- ISO 27001, HIPAA and GDPR Article 32 mappings
- Shared evidence across frameworks, mapped once
- 25 seats with roles
- Auditor view: a read-only link to the evidence pack
- Priority support with a 4 hour first response
- Quarterly readiness review with our compliance lead
Card payment opens when billing is switched on
Questions
The ones we get asked
Something else on your mind? The help centre is open, or write to us and a founder answers.
Find out where you actually stand, in about a minute
The free check is a real check. Six controls, your own material, a score you can defend and one drafted policy.
