Security & trust
Built to pass a carrier’s security review
Claims data carries health information and financial consequences. Trestl was designed around isolation, encryption, and accountability from the start, and we will walk your security team through the evidence.
- BAA available
- Encrypted in transit and at rest
- Tenant-isolated
- Platform hosted in the US
Controls
How your data is protected
Each statement below is backed by implemented controls we can demonstrate during your review.
Tenant isolation that fails closed
Encryption in transit and at rest
Least-privilege access
A tamper-evident audit trail
Hosted in the United States
Monitoring and incident response
Compliance posture
What we have, and what we do not claim
We describe our program precisely. Where an independent attestation does not exist yet, we say so.
- HIPAA
- We sign business associate agreements with clients. Our cloud provider’s BAA covers the services the platform uses, and our administrative, physical, and technical safeguards are documented and reviewed.
- SOC 2
- Controls mapped to the SOC 2 Trust Services Criteria are implemented and monitored in our internal Security Center. An independent SOC 2 attestation is on our roadmap; we do not claim one today.
- NAIC Insurance Data Security Model Law
- Our information security program maps controls to the NAIC Insurance Data Security Model Law (MDL-668), the framework many state insurance regulators apply to licensees and their service providers.
- Testing
- We test our defenses with an annual penetration test and track every finding to remediation. The 2026 test was performed in-house; an independent third-party test is planned. Dependencies and container images are scanned continuously.
Your data
Minimum necessary, agreed in advance
Before any real data is exchanged we agree the permitted purpose, the minimum necessary fields, the transfer route, retention, and the agreements that apply.
- Claims and supporting documents are processed only to deliver the agreed service, under your instructions and as our business associate agreement permits.
- AI-assisted checks run on Google Cloud Vertex AI inside our Google Cloud business associate agreement; customer content is not used to train models.
- Retention follows your agreement and our data retention policy; data is returned or securely destroyed when the agreement ends, as the agreement specifies.
- Our public website runs as a separate service with no access to claims data, and asks visitors not to send health information. See the Privacy Policy.
Responsible disclosure
Found a security issue? Tell us.
Email us with the subject line “Security” and enough detail to reproduce the issue. We acknowledge reports within two business days and do not pursue researchers who act in good faith and avoid accessing others’ data.
Frequently asked questions
- Will Trestl sign a business associate agreement?
- Yes. Where Trestl processes protected health information for a covered entity or its business associate, we sign a BAA before any data is exchanged. Whether a BAA applies depends on the entities and the data involved, which we confirm during discovery.
- Does Trestl have a SOC 2 report?
- Not yet. Controls mapped to the SOC 2 Trust Services Criteria are implemented and monitored, and we can walk your security team through them and the supporting evidence. An independent attestation is on our roadmap.
- Is our claims data used to train AI models?
- No. AI-assisted checks on claims use Google Cloud Vertex AI inside our Google Cloud business associate agreement, and Google Cloud’s service terms prohibit using customer content to train or fine-tune its models.
- Where is our data stored?
- In Google Cloud regions in the United States. An organization policy prevents resources from being created outside US locations.
- How do we send claims data securely?
- Through an agreed route: SFTP, API polling, a Google Cloud Storage exchange, or an authenticated ingest API with a key issued for your organization. We agree the route, the minimum necessary data, and retention before any real data is sent.
- How do we report a security concern?
- Email our team with the subject line “Security” and enough detail to reproduce the issue. We acknowledge reports within two business days and do not pursue researchers who act in good faith.
Bring your security questionnaire
We will walk your security and privacy team through our controls, policies, and supporting evidence as part of discovery.