FillTrust

Questions

Asked before signing, and after.

What the product reads, what it refuses to do, and what happens to your documents once they are in it.

You upload your core security documents -- SOC 2 report, ISO 27001 certificate, security whitepapers, internal policies -- to your knowledge base. We split them into passages and store an embedding of each one, scoped to your account. When a question arrives, we retrieve the passages that actually address it and answer from those, rather than from anything the model happens to know about companies in general.

No. We call Google and OpenAI through their standard business APIs, whose terms exclude API content from training their models. To be precise about what that does and does not mean: it is a contractual commitment not to train on your content, and providers may still retain it briefly for abuse monitoring under their own published policies. We do not have a zero-retention agreement with either provider, and we would rather say so than imply a guarantee we have not bought. Every subprocessor that touches your data is listed on our security page.

FillTrust says so instead of inventing one. Each answer is labelled with where it stands -- confirmed in your documents, implied but not stated, or not covered at all -- and only the uncertain ones are put in front of you. For a question nobody at your company can answer from a document, you can send that single question to the colleague who does know; they reply by email without needing an account, and their answer is saved for next time.

For your knowledge base: PDF, Word, Excel, PowerPoint, HTML, CSV, JSON, Markdown and plain text, or a .zip of any of them. For the questionnaires you are sent: Excel (.xlsx, .xlsm and legacy .xls), PDF and Word. An .xls is converted to .xlsx on upload and answered as that. It is the one case where the file you get back is not the same format you sent, because nothing can rewrite a pre-2007 binary workbook without discarding its formatting anyway. Excel is the common case for CAIQ, SIG, ISO 27001 checklists and bespoke vendor assessments, and it is the one where we return the workbook you were sent with its formatting intact. PDF and Word questionnaires come back with a formatted answers appendix, because rewriting someone else's document in place is how documents get corrupted.

Yes. The parser reads the data validation rules in the workbook, so where a sheet only accepts "Yes / No / N/A", the answer written into that cell is one of those exact options. Styling, merged cells and macros in .xlsm workbooks are preserved, so the file you send back is the file they sent you, filled in.

Every answer you approve is kept in your answer library. When a later questionnaire asks the same thing in different words, the approved answer is reused rather than regenerated -- and it is labelled as reused, so you can see which answers came from your own past decisions. This is why a second questionnaire takes noticeably less of your attention than the first. It is a library of your approved text, not a model trained on your data.

Yes, and the product is built on the assumption that you will. It is a drafting tool that shows its sources, not an autopilot. Nothing is sent anywhere on your behalf -- the completed file leaves only when you download it. What FillTrust changes is that you review four uncertain answers instead of re-reading two hundred.

Something not covered here?

Ask directly. A person answers, and if it turns out others need it too, it ends up on this page.

Contact usAnswering one right now?