Built for the kind of data trusts carry

Trust documents contain Social Security numbers, financial accounts, and the legal instructions for your family's future. Security is the foundation of the platform, not a feature.

ACCESS

You decide who sees what

Trust membership controls everything. Access comes from being on the trust with a role the holder set. No membership, no access.

Restricted sharing is an awareness view: the trust name, a non-financial summary, people and roles, the viewer's own role, and recorded death and succession notifications. It never exposes funding, documents, finances, or the trust's Record.

Professional access is yours to grant. Your attorney, CPA, advisor, or insurance agent sees your trust only after you connect them.

When a successor trustee needs to act, they reach the trust through the membership you set up, not through a shared password or a handed-over login.

PROTECTION

How we protect your trust

Encryption

Your data is encrypted with AES-256 at rest. Connections between your browser and our servers use TLS 1.3.

Account security

TOTP two-factor authentication is available on every TrustHelm account. You can turn it on from the Security tab in Settings.

Data isolation and storage

Every trust is isolated with Row Level Security. Uploaded documents are kept in private storage and are available only through authorized, time-limited access.

Infrastructure

TrustHelm uses Supabase for database, authentication, and file storage infrastructure. Supabase is SOC 2 Type II certified. TrustHelm is not SOC 2 certified.

Bank connections

When you connect an account, your bank login goes to Plaid, not to TrustHelm. We never see or store your bank username or password.

AI processing

We process your documents to build your plain-English summary, your obligations, and your compliance items. Your trust is checked against a compliance database covering all 50 states and Washington D.C., maintained internally.

Firm access and AI

Firms can connect their own AI to TrustHelm through a read-only API. A firm's key is scoped to that firm's own client book and never reaches data outside it.

Documented policies

TrustHelm adopted its Information Security, Access Control, and Data Retention and Disposal policies in August 2026.

Security contact

Report a security concern to security@trusthelm.ai. For privacy requests, email privacy@trusthelm.ai.

Your trust deserves real protection

Upload your trust, review your obligations, and keep records in one place. Free forever.