Skip to main content
TrustCited
Security

Designed for security-sensitive workflows.

TrustCited exists to make customer assurance more honest. That starts with being precise about what this platform does and does not yet do.

Status note: TrustCited is in customer validation. The items below are product and security principles being designed toward, not all shipped and audited features. Where something is not yet live, we say so.

Principles

The rules the platform is being built on.

Each principle below will map to concrete, verifiable controls as the product ships. None of them should be read as an independent audit result.

  • Tenant isolation

    Product principle

    Customer evidence is designed to be isolated by workspace in the production product. One customer's documents and answers are never visible to another.

  • Encryption

    Product principle

    Production infrastructure is designed to encrypt sensitive data in transit and at rest. Encryption requirements will apply to backups and exports too.

  • Explicit deletion

    Product principle

    Deleting evidence or a questionnaire will be explicit and will include downstream copies such as caches and derived answers.

  • Auditability

    Product principle

    Drafts, edits, approvals and exports will leave a traceable history, so you can always reconstruct how an external answer came to exist.

  • Controlled model-provider access

    Design decision

    Model providers will be used under contracts that prohibit training on customer material, with access limited to what drafting requires.

  • Human approval

    Live workflow principle

    TrustCited never submits answers externally. A named human approves every answer before it leaves your team.

  • Minimal retention

    Product principle

    Questionnaire material will be retained only as long as the workflow needs it, then removed on schedule or on request.

  • EU-first infrastructure strategy

    Design decision

    The target architecture hosts customer content within the EU, with data flows documented and minimized.

Handling practices

How pilot material is treated.

  • What TrustCited asks you to share

    During a pilot: one customer questionnaire and the documentation you would normally use to answer it. No production data, no customer personal data, no credentials.

  • What we never ask for

    Live production access, personal data of your end customers, secrets, or anything you are not comfortable sharing with a vendor in evaluation.

  • How pilot material is handled

    Shared pilot material is used only to run your pilot, is stored with restricted access, and is deleted on request or at pilot end. Nothing is used to train models.

  • What we do not claim

    TrustCited is not certified under SOC 2, ISO 27001 or any other scheme today. We will only publish certification claims once certificates actually exist.

Questions about how we handle your material?

Ask us anything before you share a questionnaire. We would rather answer hard questions now than make claims we cannot support.