Security
Security and privacy. Your security evidence deserves the same care you give it.
Trustbird holds the policy, risks and evidence of your management system. That asks for the same measures you expect from your own suppliers: EU hosting, separation between customers, encryption, strict access and a record of every change.
- Hosted in the European Union
- Strict separation between customers
- No training on customer data
How we protect your data
These are the measures that apply to every customer. If your auditor or your own customers ask how Trustbird handles your data, this is where the answer starts.
Hosting in the European Union
Trustbird runs on Laravel Cloud in the Frankfurt region, Germany. The application, the database and its backups all stay there, so your data is stored and processed in the European Union. We sign a data processing agreement with every customer, in line with the GDPR.
Strict separation between customers
The data of every organization is kept strictly apart and is only ever shown to its own users.
Encryption in transit and at rest
All traffic to Trustbird is encrypted, and stored data and backups are encrypted as well.
Access control with MFA
Users sign in with multi-factor authentication. Every user has one role per workspace: owner, member or advisor. A consultant joins as an advisor guest with read and comment access, and you switch on edit rights per part.
Audit trail on every change
Every change to your data is recorded: who created, changed or deleted which record, when, and what the old and new values were. You can show that trail to your auditor.
Backups
Customer data is backed up regularly and stored encrypted in the European Union, so it can be restored when needed.
Traceable by design
-
01
Provenance on imported records
An imported record keeps the original moment of the event, its source and the source record id, next to the moment of import. Your history stays intact.
-
02
AI judgements are recorded
For every judgement by the assistant, Trustbird records which model, which prompt version and which input were used, and at what moment. It has its own status, separate from your decisions.
-
03
No training on your data
Your data is not used to train AI models. It is used only to do the work you ask Trustbird to do.
-
04
Responsible disclosure
Found a vulnerability? Report it to support@trustbird.com. We confirm receipt, investigate and keep you informed while we fix it.
Frequently asked questions
- Is Trustbird itself certified?
- This page describes the measures we take. For questions about our own security, or to request more information for a supplier assessment, email support@trustbird.com.
- Do you use my data to train AI models?
- No. Your data is used only to do the work you ask for. For every AI judgement, Trustbird records the model, prompt version, input and moment, and a person decides what counts.
- How do I exercise my privacy rights?
- Send your request to support@trustbird.com. We handle requests for access, correction, deletion or portability in line with the GDPR.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.