Enterprise-Grade Security

Trellis is built on industry-leading infrastructure with multiple layers of protection for sensitive educational information. Your district's data security and privacy is our top priority.

Our Commitment to Security

We understand that educational institutions handle sensitive information about teachers, students, and staff. That's why we've built Trellis with security and privacy as foundational principles, not afterthoughts. Every aspect of our platform is designed to protect your data and maintain compliance with educational privacy standards.

Industry Certifications

Our AI infrastructure maintains the highest security standards through rigorous third-party audits and certifications:

  • SOC 2 Type 2Rigorous security controls audited annually by independent third parties
  • ISO 27001International standard for information security management systems
  • ISO 42001AI management system certification ensuring responsible AI practices
  • HIPAA CompliantHealthcare-grade data protection standards applied to all data
  • CSA StarCloud Security Alliance certification for cloud security excellence

Data Protection

Your sensitive data is protected at every layer with enterprise-grade security measures:

  • End-to-end encryptionData encrypted in transit (TLS 1.3+) and at rest (AES-256)
  • Zero data retentionAI providers never train on your data or retain it after processing
  • Isolated databasesEach district's data is completely separate with row-level security
  • Regular backupsAutomated backups with point-in-time recovery capabilities
  • 2FA authenticationMulti-factor authentication for enhanced account security

Privacy First

We're committed to protecting teacher and student privacy with comprehensive safeguards:

  • FERPA compliantFull compliance with Family Educational Rights and Privacy Act
  • Role-based accessGranular permissions ensure staff only access what they need
  • Comprehensive audit logsTrack every data access and change with detailed logging
  • Data ownershipYour data belongs to you, always. We never sell or share it.
  • Easy data exportDownload your complete data set anytime in standard formats

Reliable Infrastructure

Built on enterprise-grade platforms you can trust for reliability and performance:

  • Enterprise databasePostgreSQL database with Supabase infrastructure
  • 99.9% uptime SLAReliable access when you need it with guaranteed availability
  • Automatic scalingInfrastructure grows seamlessly with your district
  • Geographic redundancyData replicated across multiple regions for disaster recovery
  • 24/7 monitoringProactive threat detection and incident response

Additional Security Measures

Secure Development Practices

Regular security audits, penetration testing, and code reviews ensure our platform remains secure against emerging threats.

DDoS Protection

Enterprise-grade DDoS mitigation protects your access to the platform from malicious attacks.

Incident Response

Documented incident response procedures with immediate notification protocols for any security events.

Employee Training

All team members undergo regular security training and background checks to protect your data.

Questions about security?

We're happy to provide detailed security documentation, sign Business Associate Agreements (BAAs), and answer any compliance questions your district may have.

Compliance & Legal

Trellis is designed to help educational institutions maintain compliance with applicable laws and regulations:

  • FERPA (Family Educational Rights and Privacy Act) – We comply with all FERPA requirements for protecting student and educational records.
  • COPPA (Children's Online Privacy Protection Act) – Our platform follows COPPA guidelines for any data related to children under 13.
  • State Privacy Laws – We maintain compliance with state-specific privacy requirements including California's Student Privacy Laws.
  • Data Processing Agreements – We're happy to execute DPAs with districts to formally document our data handling responsibilities.