Skip to content
Trellis

Security

What happens to the material you give us

You are considering handing a compliance product your policies and your access tickets. That deserves a straight answer rather than a page of badges, so this page says what we collect, where it goes and how to get rid of it.

The short version

  • Your material does not train a model.
  • It goes to one model provider, to produce your result.
  • Delete your workspace and it is gone within 30 days.
  • We have no write access to any system of yours.

Practices

How we handle data

What we collect

Your account details, and the material you submit for a readiness check: pasted policies, ticket exports, settings dumps and questionnaire answers. We do not ask for production credentials and Trellis has no write access to any system of yours.

What we send to a model provider

The material you submit for a run, plus the control catalog, is sent to the routed model provider to produce your result. Nothing else leaves. Account details, billing data and support messages are never sent to a model provider.

Training

Your material does not train a model. We use providers under agreements that prohibit training on our API traffic, we do not fine-tune on customer content, and we do not use one customer's material to improve another customer's results.

Retention

Material you submit is retained for as long as the workspace exists so you can revisit a run. Delete a run and the submitted material goes with it. Delete the workspace and everything goes, including runs, drafts and submitted material, within 30 days across backups.

Encryption

In transit, TLS 1.2 or better on every connection. At rest, AES-256 on the managed stores our platform provider offers. Passwords are stored as a scrypt hash with a per-account salt and are unreadable by anyone here.

Access inside Trellis

Access to production is restricted to the engineers who need it, through single sign on with a second factor enforced. Access to customer material is limited to responding to a support request you opened, and every such access is logged.

Availability

The application and the readiness engine run on managed infrastructure in United States regions. Our status page carries current state and the history of anything that went wrong.

Reporting a problem

Write to security@trelliscore.co. We answer security reports within one business day, we will not threaten a researcher acting in good faith, and we will credit you if you would like that.

Subprocessors

Everyone who touches your data

This is the whole list. We will post here before adding to it, and a customer on an annual plan gets notice by email.
SubprocessorPurposeDataRegion
VercelApplication hosting and edge networkRequest data, application logsUnited States
OpenAIModel provider for mapping and draftingMaterial submitted for a readiness runUnited States
StripeSubscription billingBilling contact and payment metadata. Card details never touch our systems.United States

Our own posture

The questions a reviewer asks us

A compliance company that dodges these questions is telling you something.

Is Trellis itself SOC 2 certified?

Not yet, and we are not going to imply otherwise on the website of a compliance company. We are preparing on the same framework we sell, using our own product, and we will publish the report when we have one. Ask us where we are and we will tell you honestly.

Can we self-host?

Not today. The open model candidate in our routing table exists because self-hosting is on the roadmap for teams who cannot send policy text to a third party. If that is you, write to us and we will tell you where it stands rather than guessing at a date.

Will you sign our data processing agreement?

Yes. Send it to legal at the address below and we will review it. We also publish our subprocessor list above, which is usually the first thing your reviewer wants.

Something to report, or a question we did not answer

security@trelliscore.co for security, privacy@trelliscore.co for privacy and deletion requests.