Skip to content

Security & trust

Built to pass a carrier’s security review

Claims data carries health information and financial consequences. Trestl was designed around isolation, encryption, and accountability from the start, and we will walk your security team through the evidence.

  • BAA available
  • Encrypted in transit and at rest
  • Tenant-isolated
  • Platform hosted in the US

Controls

How your data is protected

Each statement below is backed by implemented controls we can demonstrate during your review.

Tenant isolation that fails closed

Every client’s data is separated by row-level security in the database. If a request arrives without a valid tenant context, it sees no rows at all, never another client’s.

Encryption in transit and at rest

Connections use TLS. Stored data is encrypted at rest, and stored files are protected with encryption keys we manage in Google Cloud KMS with scheduled rotation.

Least-privilege access

Single sign-on, role-based permissions scoped to each client, and automatic sign-out after 30 minutes of inactivity. Privileged actions such as viewing as another user are recorded.

A tamper-evident audit trail

Access to claims data and administrative actions are written to an append-only, hash-chained audit ledger that is verified daily.

Hosted in the United States

The platform runs in US Google Cloud regions, enforced by an organization policy that restricts where resources can be created.

Monitoring and incident response

Automated detections open records in an incident register, backed by a documented incident response plan and breach-notification procedures.

Compliance posture

What we have, and what we do not claim

We describe our program precisely. Where an independent attestation does not exist yet, we say so.

HIPAA
We sign business associate agreements with clients. Our cloud provider’s BAA covers the services the platform uses, and our administrative, physical, and technical safeguards are documented and reviewed.
SOC 2
Controls mapped to the SOC 2 Trust Services Criteria are implemented and monitored in our internal Security Center. An independent SOC 2 attestation is on our roadmap; we do not claim one today.
NAIC Insurance Data Security Model Law
Our information security program maps controls to the NAIC Insurance Data Security Model Law (MDL-668), the framework many state insurance regulators apply to licensees and their service providers.
Testing
We test our defenses with an annual penetration test and track every finding to remediation. The 2026 test was performed in-house; an independent third-party test is planned. Dependencies and container images are scanned continuously.

Your data

Minimum necessary, agreed in advance

Before any real data is exchanged we agree the permitted purpose, the minimum necessary fields, the transfer route, retention, and the agreements that apply.

  • Claims and supporting documents are processed only to deliver the agreed service, under your instructions and as our business associate agreement permits.
  • AI-assisted checks run on Google Cloud Vertex AI inside our Google Cloud business associate agreement; customer content is not used to train models.
  • Retention follows your agreement and our data retention policy; data is returned or securely destroyed when the agreement ends, as the agreement specifies.
  • Our public website runs as a separate service with no access to claims data, and asks visitors not to send health information. See the Privacy Policy.

Responsible disclosure

Found a security issue? Tell us.

Email us with the subject line “Security” and enough detail to reproduce the issue. We acknowledge reports within two business days and do not pursue researchers who act in good faith and avoid accessing others’ data.

Report a security issue

Frequently asked questions

Will Trestl sign a business associate agreement?
Yes. Where Trestl processes protected health information for a covered entity or its business associate, we sign a BAA before any data is exchanged. Whether a BAA applies depends on the entities and the data involved, which we confirm during discovery.
Does Trestl have a SOC 2 report?
Not yet. Controls mapped to the SOC 2 Trust Services Criteria are implemented and monitored, and we can walk your security team through them and the supporting evidence. An independent attestation is on our roadmap.
Is our claims data used to train AI models?
No. AI-assisted checks on claims use Google Cloud Vertex AI inside our Google Cloud business associate agreement, and Google Cloud’s service terms prohibit using customer content to train or fine-tune its models.
Where is our data stored?
In Google Cloud regions in the United States. An organization policy prevents resources from being created outside US locations.
How do we send claims data securely?
Through an agreed route: SFTP, API polling, a Google Cloud Storage exchange, or an authenticated ingest API with a key issued for your organization. We agree the route, the minimum necessary data, and retention before any real data is sent.
How do we report a security concern?
Email our team with the subject line “Security” and enough detail to reproduce the issue. We acknowledge reports within two business days and do not pursue researchers who act in good faith.

We will walk your security and privacy team through our controls, policies, and supporting evidence as part of discovery.