TrustFill · gettrustfill.com

Security

An honest overview of how we protect TrustFill customer data and how the product keeps humans accountable for questionnaire answers. Not a SOC 2 report, ISO certificate, or penetration-test attestation.

Last updated: July 17, 2026

1. Summary

TrustFill is operated by TWT EXPERTS LLC at gettrustfill.com. We help teams draft cited answers to security questionnaires from an evidence vault. Customers entrust us with sensitive security documentation — we take that seriously.

Ask hello@gettrustfill.com if you need a questionnaire filled about TrustFill itself. We will not invent certifications we have not earned.

2. Human approval

AI drafts answers; customers approve before export. Nothing in TrustFill submits a questionnaire to your buyer on your behalf. Reviewers can edit drafts, reject them, or leave rows unresolved until evidence exists.

  • Draft ≠ approved ≠ exported
  • Workspace members control who can approve
  • You remain accountable for what you send to customers

3. Evidence citations

Supported drafts point at vault sources (document + excerpt) so reviewers can verify the claim. Citations are a productivity and accountability aid — not a guarantee that a buyer or auditor will accept the answer.

4. UNVERIFIED workflow

When retrieval finds no supporting evidence, TrustFill marks the answer UNVERIFIED rather than inventing a confident “yes.” That gap is intentional: it surfaces missing proof instead of hiding it behind fluent language.

  • Add evidence and regenerate, or answer manually
  • Do not treat UNVERIFIED as “probably fine”
  • Export should reflect what your team actually approved

5. Authentication & access

  • Users authenticate before accessing workspace features
  • API routes that touch customer data require a valid session
  • Workspace data is scoped in application logic to the authenticated workspace
  • Customers control invites — treat them as privileged
  • Operational access to production systems is limited to people who need it

6. Encryption & transit

  • In transit — Production traffic uses HTTPS/TLS
  • Payments — Card data is handled by Stripe; we do not store full payment card numbers
  • At rest — Database and file storage follow our hosting providers’ encryption defaults (Supabase / Vercel ecosystem). Ask us if procurement needs a deeper questionnaire on TrustFill itself.

7. Privacy

We store account email, workspace metadata, uploaded evidence / extracted text, questionnaire content, drafts, citations, approvals, export-related records, Stripe identifiers, and operational logs. Details and rights are in our Privacy Policy.

Evidence and questionnaire text may be sent to commercial LLM APIs to generate drafts. We do not use your vault to train public models for unrelated third parties. Only upload documents you are allowed to share with a SaaS vendor and its subprocessors.

8. Infrastructure

  • Application hosting — Vercel (production: gettrustfill.com)
  • Database — Postgres on Supabase (TrustFill-prefixed tables)
  • Payments — Stripe (merchant: TWT EXPERTS LLC)
  • AI drafting — Commercial LLM APIs receive relevant evidence and question excerpts

9. Incidents & shared responsibility

If we become aware of a security incident affecting your personal data or Customer Content, we will investigate and notify affected customers as required by law and as reasonably practical. Report issues to hello@gettrustfill.com with subject “Security”.

  • Use strong email account security; magic links inherit inbox security
  • Invite only trusted teammates
  • Review drafts before export
  • Remove stale evidence and deactivate users who leave

10. What we will not claim

As TrustFill grows, we expect to deepen formal controls. This page will update as those land. We will not claim SOC 2, ISO, or other certifications we have not earned, and we will not market AI drafts as audit-ready without human review.

11. Contact

TWT EXPERTS LLC (TrustFill)
Security / privacy: hello@gettrustfill.com
Web: https://gettrustfill.com
Product walkthrough: /demo · Book: /book-demo