Trust & Security

    Security at Trussed AI

    Trussed AI is delivered as software that customers install, configure, and operate within their own environments. Our security program is built around shipping secure software, supporting customers who run it, and protecting the corporate systems behind it.

    Customer-deployed by design

    Trussed AI does not operate production infrastructure on customers' behalf and does not process customer data in a Trussed-operated service. Deployments run in the customer's cloud accounts, on-premises data centers, or hybrid environments. This shapes how responsibility is divided between Trussed AI and the customer, and is described in detail in our Customer Shared Responsibility Policy.

    Read the Shared Responsibility Policy

    Our security program

    The pillars below summarize the controls Trussed AI is accountable for as the producer of the software. Each is governed by an internal policy and reviewed at least annually.

    Secure Software Development

    Peer review, automated testing, static analysis, dependency scanning, and secret scanning are applied to every change to the Trussed AI codebase. Build, signing, and release infrastructure is hardened and access-controlled.

    Supply Chain Integrity

    Source control, build pipelines, and signing keys are protected from unauthorized use or modification. A software bill of materials is maintained for shipped releases and available to customers on reasonable request.

    Vulnerability Management

    Vulnerabilities in shipped software are tracked to resolution and patched commensurate with severity. Affected customers are notified in time to take protective action in their own environments.

    Product Security Capabilities

    Trussed AI ships with authentication primitives, encryption in transit, audit logging, prompt and response inspection, policy enforcement, and data filtering, configurable to match each customer's regulatory posture.

    Corporate Information Security

    Internal systems that develop, build, sign, and ship the software, along with supporting business systems and Personnel devices, are governed by the Information Security Policy and its subordinate controls.

    Customer Information Handling

    Customer information shared with Trussed AI for sales, support, or contractual purposes is protected under the Access Control Policy, retained only as long as needed, and deleted, returned, or anonymized when no longer required.

    Compliance posture

    Because customers operate their own Trussed AI deployments, regulatory compliance for any given deployment rests with the customer. Trussed AI software provides capabilities that support major regimes, including SOC 2, HIPAA, the NAIC Model Bulletin on AI, NYDFS Circular Letter No. 7, the EU AI Act, and GDPR, through policy enforcement, data filtering, and audit evidence generation.

    Trussed AI responds to customer security inquiries, questionnaires, and due diligence requests, and provides summaries of its security program, copies of relevant policies, and third-party attestations where available. Reach out to hello@trussed.ai to start a review.

    Vulnerability disclosure

    We accept vulnerability reports from customers and external security researchers. Please include sufficient detail to reproduce the issue, an assessment of potential impact, and any relevant context. Trussed AI does not pursue legal action against good-faith research conducted in accordance with this policy.

    Report a vulnerability

    Security contact

    For all security-related communication, including vulnerability reports, security questionnaires, incident coordination, and policy requests, contact our security team directly.

    hello@trussed.ai

    Policies and references

    The most current versions of our customer-facing policies are available on the Trussed AI website.