Built for the kind of data trusts carry

Trust documents contain Social Security numbers, financial accounts, and the legal instructions for your family's future. Security is the foundation of the platform, not a feature.

THE FOUR PILLARS

How we protect your trust

Encrypted end to end

AES-256 at rest, TLS 1.3 in transit

Every document, every database record, every API call. Encryption keys are managed by our infrastructure providers and rotated automatically.

Private by default

We never sell your data and never train AI models on it

Your documents are stored in private buckets only your account can access. AI processing happens on your data only when you request it.

Strict access control

Row-level security and trust-membership permissions

Database-level isolation means no trust can ever see another trust’s data. Every API request is authenticated and scoped to your membership.

Your data, your call

Export anytime. Delete anytime. No data ransom.

Bulk document downloads, full data exports in PDF or CSV, and one-click account deletion. We honor CCPA and GDPR data subject requests.

ARCHITECTURE

Three layers, working together

Every request passes through three independent layers of protection.

Edge Network

DDoS protectionGlobal CDNHTTPS everywhere

Your connection is encrypted and accelerated globally before it reaches our servers.

Application Security

AuthenticationInput validationRate limiting

Every request is authenticated and validated before touching your data.

Data Protection

Row-level securityAES-256 encryptionPrivate storage

Each trust’s data is isolated using database-level access policies.

THE DETAILS

What’s under the hood

Encryption

TrustHelm encrypts data end to end. Documents are encrypted with AES-256 before they're written to storage. Connections between your browser and our servers use TLS 1.3. Database records sit on encrypted volumes managed by our infrastructure providers.

Data ownership

Your trust documents and records belong to you. You can export them at any time in PDF or CSV format, download every document you've uploaded as a single archive, and delete your account with one click. Account deletion removes your data from production immediately and from backups within 30 days.

Infrastructure

TrustHelm runs on U.S.-based infrastructure providers that hold SOC 2 Type II certification. We use established cloud providers for hosting, database, and storage so we inherit their physical security, redundancy, and monitoring. Vendor names are available on request for legal due diligence.

AI processing

AI processes your documents only when you request it. We never use your documents to train AI models. Our AI cross-references your trust against a compliance database covering trust statutes for all 50 U.S. states and Washington D.C., maintained internally.

Access control

Every request is authenticated. Row-level security at the database layer ensures no trust can ever access another trust's data. Trust membership determines what each person on a trust can see and edit. Restricted beneficiary roles (coming soon) will see only what they're entitled to, never financial detail.

Privacy compliance

We honor CCPA and GDPR data subject requests. California residents can request access, export, and deletion of all personal data we hold. EU residents have the same rights plus full data portability and the right to erasure. Email privacy@trusthelm.ai with any request.

Your trust deserves real protection

Upload your trust, review your duties, and keep records in one place. Free forever.