Security & Trust

How we protect your data

Tenant isolation

Case data

Your case data is held in a dedicated, single-tenant database.

Documents

Your documents are held in dedicated, single-tenant storage.

Encryption

In transit

All connections are encrypted in transit with TLS 1.2+.

At rest

Data is encrypted at rest with AES-256 across every database and document store.

Credentials

Integration tokens and API keys are encrypted again at the application layer, with a key held outside the database.

Access & hosting

Access control

Production access is restricted to authenticated Trellys staff.

Data residency

Your data is stored in the United States.

Data lifecycle

Data minimization

We retain only the data needed to run your workflows. Data without an active purpose is not kept.

Secure deletion

Your data and documents are deleted on request when you leave.

AI

No training

Your content is not used to train AI models.

Not retained

Your content is not retained by the AI provider after processing.

Your keys

Firms can run AI on their own provider API keys.

Compliance

HIPAA

Trellys is HIPAA compliant. We sign a Business Associate Agreement on request.

Breach notification

If a breach affects your protected health information, we notify your firm without unreasonable delay and no later than 60 days after discovery, as required by HIPAA.

Subprocessors

A current list of our subprocessors is available on request.

Infrastructure

Trellys runs on SOC 2–audited cloud infrastructure.

Insurance

Coverage

Trellys carries professional liability, cyber, and general liability insurance. A certificate of insurance is available on request.

Operations

Incident response

Incidents are handled by the Trellys engineering team. Phone: +1 (817) 508-2702. Member firms have a dedicated escalation line.

Backups

Encrypted database backups run daily.

Need this for a vendor review?

Request our security packet, a certificate of insurance, and a Business Associate Agreement.

Request the security packet