Trellios
Security at Trellios

Security Isn't a Feature.
It's the Foundation.

Every architectural decision at Trellios starts with a security question. When your AI workforce handles business-critical work, the infrastructure underneath it has to be trustworthy.

Core principles

How we think about security

Security isn't a checklist we run before launch. It's a set of principles that shapes every technical decision we make.

Encryption in transit and at rest

All data transmitted to and from Trellios is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. There is no unencrypted path into or out of the platform.

Role-based access control

Every user, agent, and integration operates with the minimum permissions required for its role. Privilege escalation requires explicit authorization. Access is auditable and revocable.

Complete audit logging

Every agent action, workflow execution, approval decision, and configuration change is logged with timestamps and actor attribution. Nothing is untracked.

Responsible AI data practices

We train AI models on your data only with your explicit consent. Your data stays yours, and we are transparent about what we process and why.

Data protection

How we protect your data

  • Data residency

    Trellios infrastructure is hosted in US-based data centers. We do not transfer customer data to jurisdictions without your knowledge.

  • No unauthorized training

    We train AI models on your content and workflow data only with your explicit, informed consent. Never by default.

  • Subprocessor controls

    We maintain a list of subprocessors and conduct due diligence on every vendor that handles customer data. Changes to this list are communicated in advance.

  • Incident response

    We maintain documented incident response procedures and commit to timely disclosure in the event of a breach affecting customer data.

Compliance

Current status

GDPR / CCPA
Compliant
SOC 2 Type II
In progress
HIPAA
Not applicable

Responsible disclosure

If you have discovered a potential security vulnerability in Trellios, please contact us directly. We are committed to working with security researchers in good faith, and we will acknowledge and respond to every credible report.

Report a vulnerability

legal@trellios.ai

See the platform in action

Book a walkthrough and see how Trellios governs AI agent activity across a real workflow.

Book a demo