Security built for enterprise real estate.

Trebellar keeps your portfolio data safe with enterprise-grade security, governance, and privacy controls.

Explore Trebellar Trust Center

Enterprise-Grade Protection

  • Purpose-Built Security

    SOC 2 Type II certified, hosted in a private Google Cloud VPC, with TLS + client-certificate authentication and SSO/SAML support.

  • Data Sovereignty & Control

    You own your data. Set retention terms, export or delete anytime, and choose your hosting region if required.

  • No Model Training

    Your data is never used to train third-party models, and Trebellar’s own models are trained and applied per customer, never shared.

  • De-Identified by Design

    PII and sensitive identifiers are stripped before any data reaches a Large Language Model (LLM), internal or external.

  • Least-Privilege by Design

    Every AI agent accesses only the specific data and internal APIs it needs to do its job — nothing more.

  • Independently Tested

    Continuous testing across dev, staging, and production, plus third-party vulnerability testing results available on request.

Certifications

  • SOC 2 Type II

    Certified since July 2024.

    See Details
  • GDPR

    Compliant data handling practices, including hashing for any PII identifiers.

    See Details

FAQ

Security is fundamental

We’ve built a system that protects data at every level — from authentication to AI governance. Security isn’t a feature we added; it’s a constraint the whole platform was designed around from day one.

Still have a question?

Talk to Us
  • How does Trebellar define customer data?

    Anything you provide directly (building assets, floor plans, user profiles) plus data generated by systems and sensors you authorize (badge, WiFi, IoT, HRIS). You own all of it.

  • How does Trebellar keep my data private and secure?

    All data is encrypted in transit via TLS 1.2 or greater and client certificates. Access is authenticated via SSO/SAML, monitored, and logged.

  • Where is my data hosted and processed?

    Hosted on Google Cloud in a private, cross-region US VPC. Other regions are available if required.

  • How do you respect access controls for my data?

    Trebellar staff have no access to customer data unless explicitly requested and configured by your admin. Every request is authenticated and authorized at the service level.

  • How does Trebellar ensure no one is training on my data?

    LLMs never access raw data directly — everything is mediated through internal APIs and de-identified before processing. External LLM providers (OpenAI Enterprise, Gemini Enterprise) are contractually guaranteed not to train on submitted data.

  • Can my organization’s data be used to improve Trebellar’s own models?

    Trebellar’s proprietary ML models are trained and applied per customer only. Insights and models built from your data are never shared across organizations.

  • How often do you perform security audits and vulnerability assessments?

    Trebellar undergoes regular third-party vulnerability testing, with results available on request, alongside continuous internal testing across every release.

  • Is Trebellar SOC 2 compliant?

    Yes, since Q3 2024 (SOC 2 Type II).

  • Do I need to connect Trebellar directly to my production systems?

    No. Many customers start with a CSV upload or secure file sync with no direct system connection required. Deeper integration (API, direct warehouse) is available later, on your own timeline.

  • How do I request that my data be deleted?

    Email security@trebellar.com with your name, company name, and contract end date.

  • Can I turn off Trebellar’s AI features?

    Yes. AI features can be disabled fully or partially, without losing core platform access.

Getting started doesn’t mean opening a door into your production systems.

Trebellar offers multiple ways to get your data in — you choose the path that matches your systems, timeline, and IT comfort level.

  • Manual CSV Upload

    Fastest time-to-value.

    Typical setup: 2–3 weeks.

  • Direct Warehouse Integration

    Native connection to Snowflake, BigQuery, and similar.

    Typical setup: 2–4 weeks.

  • Secure File Sync

    SFTP / Cloud Storage — automated ingestion, minimal IT lift.

    Typical setup: 3–4 weeks.

  • API Integration

    Fully automated, real-time ingestion at scale.

    Typical setup: 4–6 weeks.

Most customers begin with CSV or SFTP, then move to API integration over time.

What IT Wants to Know About Trebellar

Vetted by some of the most rigorous security teams in the world.

Trebellar works with IT and security teams at Fortune 50 companies.

  • Meta
  • Uber
  • Merck

See Trebellar in action and learn how we protect your portfolio data.

Get a Demo