Security
What happens to the material you give us
The short version
- Your material does not train a model.
- It goes to one model provider, to produce your result.
- Delete your workspace and it is gone within 30 days.
- We have no write access to any system of yours.
Practices
How we handle data
What we collect
Your account details, and the material you submit for a readiness check: pasted policies, ticket exports, settings dumps and questionnaire answers. We do not ask for production credentials and Trellis has no write access to any system of yours.
What we send to a model provider
The material you submit for a run, plus the control catalog, is sent to the routed model provider to produce your result. Nothing else leaves. Account details, billing data and support messages are never sent to a model provider.
Training
Your material does not train a model. We use providers under agreements that prohibit training on our API traffic, we do not fine-tune on customer content, and we do not use one customer's material to improve another customer's results.
Retention
Material you submit is retained for as long as the workspace exists so you can revisit a run. Delete a run and the submitted material goes with it. Delete the workspace and everything goes, including runs, drafts and submitted material, within 30 days across backups.
Encryption
In transit, TLS 1.2 or better on every connection. At rest, AES-256 on the managed stores our platform provider offers. Passwords are stored as a scrypt hash with a per-account salt and are unreadable by anyone here.
Access inside Trellis
Access to production is restricted to the engineers who need it, through single sign on with a second factor enforced. Access to customer material is limited to responding to a support request you opened, and every such access is logged.
Availability
The application and the readiness engine run on managed infrastructure in United States regions. Our status page carries current state and the history of anything that went wrong.
Reporting a problem
Write to security@trelliscore.co. We answer security reports within one business day, we will not threaten a researcher acting in good faith, and we will credit you if you would like that.
Subprocessors
Everyone who touches your data
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Vercel | Application hosting and edge network | Request data, application logs | United States |
| OpenAI | Model provider for mapping and drafting | Material submitted for a readiness run | United States |
| Stripe | Subscription billing | Billing contact and payment metadata. Card details never touch our systems. | United States |
Our own posture
The questions a reviewer asks us
Is Trellis itself SOC 2 certified?
Not yet, and we are not going to imply otherwise on the website of a compliance company. We are preparing on the same framework we sell, using our own product, and we will publish the report when we have one. Ask us where we are and we will tell you honestly.
Can we self-host?
Not today. The open model candidate in our routing table exists because self-hosting is on the roadmap for teams who cannot send policy text to a third party. If that is you, write to us and we will tell you where it stands rather than guessing at a date.
Will you sign our data processing agreement?
Yes. Send it to legal at the address below and we will review it. We also publish our subprocessor list above, which is usually the first thing your reviewer wants.
Something to report, or a question we did not answer
security@trelliscore.co for security, privacy@trelliscore.co for privacy and deletion requests.