How it works
Three steps, and only one of them is yours

Step 01
Connect your policies and settings
Bring the mess. Organising it is the job, not the prerequisite.
Paste a policy from Notion, a Google Doc or a wiki page written in 2023. Drop a ticket export covering access and offboarding. Add a settings dump from your cloud account and identity provider, and the spreadsheet where your vendors live.
Nothing needs a particular format. Trellis is reading prose, not parsing a schema, which is exactly why it can take material a form would reject.
What people bring on a first run
- An information security policy, undated
- An engineering handbook page about shipping
- Two or three access tickets
- A cloud settings export
- A vendor list on a finance tab
Step 02
Trellis maps it and flags the gaps
Every control gets a status, and every status gets a reason.
Each control in scope is assessed against everything you gave it. Met means the evidence exists and Trellis can name it. Weak means something exists but a reviewer would push back, and you are told exactly why. Missing means missing.
Anything the model offers as a supporting quote is checked against your material verbatim before you see it. A quote that cannot be found is dropped and the finding is marked unsupported. A control cannot be marked met with no evidence named, because we downgrade that in code.
The score is arithmetic on the statuses, not a number a model produced. Met counts one, weak counts a half, missing counts nothing.
Where first runs land
- Under 40: nothing written down yet
- 40 to 69: you do the work, it is not evidenced
- 70 to 89: close, usually vendors and incident response
- 90 plus: book the auditor
Step 03
Review the drafted fixes
Every gap arrives with the document that closes it.
Trellis writes the policy, the procedure or the questionnaire answer, using what it learned about you. Drafts are short on purpose, because a startup will not adopt eight pages, and every one carries an owner field, an effective date and a review cadence.
You review, edit and adopt. That adoption is the thing an auditor accepts, and Trellis never records that you adopted something you did not.
What comes out
- A drafted policy, 280 to 420 words
- An evidence checklist named the way a request list names it
- Questionnaire answers, grounded or flagged
- An export when your auditor asks
Questions
Before you start
The free check runs the same loop
Six controls, your own material, one drafted policy.