Built for the kind of data trusts carry
Trust documents contain Social Security numbers, financial accounts, and the legal instructions for your family's future. Security is the foundation of the platform, not a feature.
ACCESS
You decide who sees what
Trust membership controls everything. Access comes from being on the trust with a role the holder set. No membership, no access.
Restricted sharing is an awareness view: the trust name, a non-financial summary, people and roles, the viewer's own role, and recorded death and succession notifications. It never exposes funding, documents, finances, or the trust's Record.
Professional access is yours to grant. Your attorney, CPA, advisor, or insurance agent sees your trust only after you connect them.
When a successor trustee needs to act, they reach the trust through the membership you set up, not through a shared password or a handed-over login.
PROTECTION
How we protect your trust
Encryption
Your data is encrypted with AES-256 at rest. Connections between your browser and our servers use TLS 1.3.
Account security
TOTP two-factor authentication is available on every TrustHelm account. You can turn it on from the Security tab in Settings.
Data isolation and storage
Every trust is isolated with Row Level Security. Uploaded documents are kept in private storage and are available only through authorized, time-limited access.
Infrastructure
TrustHelm uses Supabase for database, authentication, and file storage infrastructure. Supabase is SOC 2 Type II certified. TrustHelm is not SOC 2 certified.
Bank connections
When you connect an account, your bank login goes to Plaid, not to TrustHelm. We never see or store your bank username or password.
AI processing
We process your documents to build your plain-English summary, your obligations, and your compliance items. Your trust is checked against a compliance database covering all 50 states and Washington D.C., maintained internally.
Firm access and AI
Firms can connect their own AI to TrustHelm through a read-only API. A firm's key is scoped to that firm's own client book and never reaches data outside it.
Documented policies
TrustHelm adopted its Information Security, Access Control, and Data Retention and Disposal policies in August 2026.
Security contact
Report a security concern to security@trusthelm.ai. For privacy requests, email privacy@trusthelm.ai.
Your trust deserves real protection
Upload your trust, review your obligations, and keep records in one place. Free forever.