Skip to content
Trellis

Product

It reads what you have, and writes what you do not

Trellis is not a dashboard that watches settings. It is the part of compliance that used to need a consultant: reading your material, deciding whether it satisfies a control, and producing what is missing.

In one run

  • A status for every control in scope
  • The gap said in plain language
  • Evidence you have, evidence you need
  • One drafted document, at minimum
  • A score computed in code, not guessed

Capabilities

Three things, done properly

Everything else in the product exists to make these three trustworthy.

01

Readiness check

The core run. Everything you have goes in, a status per control comes out, with the gap and the evidence still needed for each one.

Free on six controls, all 22 on Startup.

Bright abstract lattice with evidence organised onto crossing green lines

02

Drafted policies and procedures

For each gap, the document that closes it, written from your own context with an owner, an effective date and a review cadence already in place.

One per check on Free, every gap on Startup.

Bright abstract composition of a document forming from ordered green lines

03

Security questionnaire answers

Paste the questionnaire your customer sent. Trellis answers from evidence you already have and flags every answer it could not ground in something real.

Startup and Growth.

Bright abstract checklist of green and amber markers on a white field

The framework

All 22 controls, in the open

No part of the mapping is hidden behind a sales call. This is the catalog Trellis assesses against, with the six starter controls marked.

Governance

5
  • CC1.1Code of conduct and accountabilityThere is a written code of conduct, everyone has agreed to it, and someone owns it.
  • CC1.2Board and management oversightSomeone above the team reviews security at a set cadence, and there is a record of it.
  • CC2.1Security policy setThe core policies exist in writing, people have read them, and they were reviewed in the last twelve months.free
  • CC3.1Risk assessmentYou wrote down what could go wrong, how bad it would be, and what you are doing about the top items.
  • CC3.4Change in the business, reassessedWhen something big changes, a new region, a new subprocessor, a reorg, you look at the risks again.

Access

4
  • CC6.1Logical access controlsAccess to production and customer data is restricted, uses single sign on, and requires a second factor.free
  • CC6.2Access provisioningNew access is requested and approved by someone who is allowed to approve it, before it is granted.
  • CC6.3Access removal and reviewWhen someone leaves or changes role, their access changes the same day, and you review access quarterly.free
  • CC6.6Boundary protectionThe network edge is locked down: no open management ports, and remote access goes through something you control.

Change

1
  • CC8.1Change managementCode is reviewed before it ships, deploys are recorded, and nobody pushes to production alone.free

Operations

6
  • CC4.1Control monitoringYou check that the controls are actually running, not just written down, and you keep the results.
  • CC5.2Control activities in technologyThe rules are enforced by the systems where possible, not only by asking people nicely.
  • CC6.8Malware and endpoint protectionLaptops are managed, encrypted and monitored, and you can list which ones.
  • CC7.1Vulnerability managementYou scan for vulnerabilities on a schedule and fix the serious ones inside a stated window.
  • CC7.2Security monitoring and alertingLogs go somewhere central, alerts reach a human, and that human knows what to do.
  • CC7.3Incident responseThere is an incident plan with severities, roles and a customer notification path, and it has been exercised.free

Vendors

1
  • CC9.2Vendor and subprocessor managementYou keep a list of vendors that touch customer data, you reviewed each one, and the contracts say the right things.free

Availability

3
  • CC9.1Business continuityYou know what you would do if a region or a key vendor went away, and you have written it down.
  • A1.2Backups and recoveryBackups run, you have actually restored from one, and you know how long a restore takes.
  • A1.1Capacity and availability monitoringYou watch capacity and uptime, and you would know before customers did.

Confidentiality

2
  • CC6.7Encryption in transit and at restData is encrypted on the wire and on disk, and you can show the settings that make it so.
  • C1.2Data retention and disposalYou know how long you keep customer data, and deletion actually deletes it, including from backups.

6 controls in the free starter scope, 22 in the full framework.

Frameworks

One evidence set, more than one framework

Evidence collected for SOC 2 already satisfies most of what ISO and HIPAA ask for. Collecting it twice is a tax nobody should pay.

SOC 2 style (Trust Services Criteria)

22 controlsLive

Security, availability and confidentiality criteria, mapped to 22 controls.

ISO 27001 Annex A

93 controlsGrowth

Included on Growth. Shares evidence with SOC 2 where the controls overlap.

HIPAA Security Rule

54 controlsGrowth

Included on Growth. Administrative, physical and technical safeguards.

GDPR Article 32

18 controlsGrowth

Included on Growth. Security of processing, mapped to the same evidence.

Run it on your own material and see