SOC 2 Type II
Certified since July 2024.
Trebellar keeps your portfolio data safe with enterprise-grade security, governance, and privacy controls.
Explore Trebellar Trust CenterSOC 2 Type II certified, hosted in a private Google Cloud VPC, with TLS + client-certificate authentication and SSO/SAML support.
You own your data. Set retention terms, export or delete anytime, and choose your hosting region if required.
Your data is never used to train third-party models, and Trebellar’s own models are trained and applied per customer, never shared.
PII and sensitive identifiers are stripped before any data reaches a Large Language Model (LLM), internal or external.
Every AI agent accesses only the specific data and internal APIs it needs to do its job — nothing more.
Continuous testing across dev, staging, and production, plus third-party vulnerability testing results available on request.
Certified since July 2024.
Compliant data handling practices, including hashing for any PII identifiers.
FAQ
We’ve built a system that protects data at every level — from authentication to AI governance. Security isn’t a feature we added; it’s a constraint the whole platform was designed around from day one.
Still have a question?
Anything you provide directly (building assets, floor plans, user profiles) plus data generated by systems and sensors you authorize (badge, WiFi, IoT, HRIS). You own all of it.
All data is encrypted in transit via TLS 1.2 or greater and client certificates. Access is authenticated via SSO/SAML, monitored, and logged.
Hosted on Google Cloud in a private, cross-region US VPC. Other regions are available if required.
Trebellar staff have no access to customer data unless explicitly requested and configured by your admin. Every request is authenticated and authorized at the service level.
LLMs never access raw data directly — everything is mediated through internal APIs and de-identified before processing. External LLM providers (OpenAI Enterprise, Gemini Enterprise) are contractually guaranteed not to train on submitted data.
Trebellar’s proprietary ML models are trained and applied per customer only. Insights and models built from your data are never shared across organizations.
Trebellar undergoes regular third-party vulnerability testing, with results available on request, alongside continuous internal testing across every release.
Yes, since Q3 2024 (SOC 2 Type II).
No. Many customers start with a CSV upload or secure file sync with no direct system connection required. Deeper integration (API, direct warehouse) is available later, on your own timeline.
Email security@trebellar.com with your name, company name, and contract end date.
Yes. AI features can be disabled fully or partially, without losing core platform access.
Trebellar offers multiple ways to get your data in — you choose the path that matches your systems, timeline, and IT comfort level.
Fastest time-to-value.
Typical setup: 2–3 weeks.
Native connection to Snowflake, BigQuery, and similar.
Typical setup: 2–4 weeks.
SFTP / Cloud Storage — automated ingestion, minimal IT lift.
Typical setup: 3–4 weeks.
Fully automated, real-time ingestion at scale.
Typical setup: 4–6 weeks.
Most customers begin with CSV or SFTP, then move to API integration over time.
What IT Wants to Know About TrebellarTrebellar works with IT and security teams at Fortune 50 companies.