Security at Trelium
Your data, isolated, protected, and entirely yours.
From infrastructure to compliance, here's exactly how Trelium keeps what's yours yours.
Compliance
Built to clear your security review.
Our controls cover the full SOC 2 Trust Services Criteria, and our current posture is public, so your team can check it for themselves.
SOC 2 Type II
Trust Services Criteria
- Security
- Availability
- Confidentiality
- Processing integrity
Data protection
Your data stays yours.
Three commitments behind every Trelium deployment.
Never used to train AI
Nothing processed through Trelium (orders, customer records, emails, or any other business data) is used to train, fine-tune, or improve any AI model, by Trelium or any third party.
Contractually guaranteed · Applies to all subprocessors
Isolated by default
Every customer runs in a dedicated environment. There is no shared database, no shared processing pipeline, and no path from one customer's data to another's.
Dedicated environment · Infrastructure-level enforcement
Owned by you, not kept by us
We process your data on your behalf and don't store it beyond what your agents need. On contract termination, it's deleted on a defined timeline.
Customer-owned data · Defined deletion timeline
How isolation works
Enforced by infrastructure, not just the application.
Your agents, pipeline, and database live in an environment that belongs to you alone. Your data is never co-mingled with another customer's.
Your environment
- Agents
- Processing pipeline
- Database
Another customer
- Agents
- Processing pipeline
- Database
Access and oversight
You decide who gets in. You see everything agents do.
Role-based access
People see and do only what their role permits.
SSO through your identity provider
Access is managed centrally, in the tools your IT team already controls.
Instant offboarding
When someone leaves, their access ends immediately.
Full audit trails
Every read, write, decision, and handoff is logged with what happened, when, and why. Logs are tamper-resistant and exportable.
Audit trail
ExampleOrder Entry Agent
- 09:14:02ReadCustomer PO #4471 from the orders inbox
- 09:14:06WroteSales order SO-10442 in the ERP
- 09:14:07DecidedFlagged line 3: unit price differs from contract
- 09:14:07Handed offSent to M. Chen for pricing approval
Ready for your security review
Everything your procurement team needs, on day one.
No lengthy back-and-forth. The documents are ready, and so are we.
Vendor risk packet
Ready to share immediately, no chase required.
Subprocessor list
Published, current, and transparent. No surprises.
30-minute controls walkthrough
Your CTO and security team get every question answered before you sign anything.
Security FAQ
Questions your security team might ask
Trelium's SOC 2 Type II audit is in progress, covering the full Trust Services Criteria: security, availability, confidentiality, and processing integrity. A vendor risk packet and current controls documentation are available on request today.
No. Nothing processed through Trelium (orders, customer records, emails, or any other business data) is used to train, fine-tune, or improve any AI model, by Trelium or any third party. This is a contractual guarantee that applies to all of our subprocessors.
Yes. Every Trelium customer runs in a dedicated, isolated environment with no shared database or processing pipeline. Isolation is enforced at the infrastructure level, so there is no scenario in which one customer's data is accessible to another.
Your data always belongs to you. Trelium processes it on your behalf and does not retain it beyond what's necessary to run your agents. On contract termination, data is deleted on a defined timeline.
Yes. SSO integrates with your existing identity provider so access is managed centrally through the tools your IT team already controls, with role-based permissions and instant offboarding.
Our Trust Center at trust.trelium.com gives a live view of our security posture, certifications, and uptime.
Our vendor risk packet, subprocessor list, and security controls documentation are prepared and available without a lengthy back-and-forth. We can also walk your CTO and security team through our controls on a single 30-minute call.




