Security & Privacy

Trust documents are sensitive. TrustHelm protects them with encryption, strict access controls, and clear data ownership.

Your trust documents contain Social Security numbers, financial account details, and legally binding instructions for your family's future. TrustHelm was built with security as a foundation, not an afterthought. Every layer of the platform protects your most sensitive information.

Encrypted

AES-256 at rest, TLS 1.3 in transit.

Private

We will never sell your data. Period.

CCPA Aligned

Built to meet California Consumer Privacy Act standards.

GDPR Aligned

Built to meet EU General Data Protection Regulation standards.

Encryption

TrustHelm encrypts data end to end:

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • • Private storage buckets for uploaded documents

AI Infrastructure

TrustHelm AI processes your documents securely and never uses them to train AI models. Our AI cross-references your trust against a compliance database covering trust statutes for all 50 U.S. states.

Data Ownership

Your trust documents and records belong to you.

  • • Export anytime (PDF, CSV, bulk document download)
  • • Delete your account with one click
  • • Full account deletion available on request

Access Control

TrustHelm uses strict access controls for multi-tenant SaaS:

  • • Row-level security (RLS) to isolate account data
  • • Trust membership-based permissions
  • • Complete separation between different trusts

Infrastructure

TrustHelm runs on established infrastructure:

  • • Vercel (application hosting)
  • • Supabase (database, auth, storage)
  • • US-based infrastructure

Privacy Compliance

TrustHelm complies with the leading privacy regulations:

  • CCPA compliant: California residents can access, export, and delete all personal data
  • GDPR compliant: full data portability, right to erasure, and consent management

Security Architecture

Vercel Edge Network

DDoS protection · Global CDN · HTTPS everywhere

Your connection is encrypted and accelerated globally before it reaches our servers.

Application Security

Authentication · Input validation · Rate limiting

Every request is authenticated and validated before touching your data.

Data Protection

Row-level security · AES-256 encryption · Private storage

Each trust's data is completely isolated using row-level database policies.

Your trust documents deserve real protection.

Upload your trust, review your duties, and keep records in one place.