FillTrust

Security

How we handle your documents

You are about to upload your SOC 2 report and security policies to us. Here is how we handle them, stated plainly enough that you could paste it into your own questionnaire.

Last updated 2026-08-30

Encryption

Everything is encrypted in transit with TLS and at rest by Google Cloud. TOTP secrets are additionally encrypted at the application layer with AES-256-GCM, so a database read alone does not yield a working second factor.

Tenant isolation

Every API request derives its tenant from your authenticated session, server-side. No endpoint accepts a customer identifier from the browser, and a request for another tenant's data returns 404 rather than confirming the record exists.

Access control

Accounts are protected by password and optional TOTP two-factor authentication. Authentication endpoints are rate limited. Our API backend is not reachable from the public internet.

Data residency

Documents are stored in Google Cloud in Paris and the database is hosted in Frankfurt, both of them in the EU. Question text and the specific excerpts used to answer are sent to AI providers in the United States under Standard Contractual Clauses. Neither provider trains on API data.

Retention and deletion

We keep your data for as long as your account exists. Deleting your account cancels billing, removes every uploaded document and generated questionnaire from storage, and deletes your records. If any part of that cannot be completed, the deletion is aborted and reported rather than partially applied.

Auditability

Every answer change is recorded: what it was, what it became, who changed it, and when. That includes answers submitted by outside experts through a review link. Generated answers cite the passages from your own documents they were drawn from, and citations that cannot be verified against those documents lower the answer's confidence.

Monitoring

Uptime is checked continuously against the public domain, and backend errors raise an alert. Object storage is versioned, so an accidental overwrite is recoverable.

Reporting a vulnerability

Email security@filltrust.com. Tell us what you did, what happened, and how to reproduce it. We aim to acknowledge within five working days and will tell you when it is fixed.

Safe harbour. We will not pursue legal action over good-faith research that stays within this scope: test only against your own account, do not access, modify or retain another customer's data, do not run denial of service or automated scanning that degrades the service for others, and give us a reasonable chance to fix the issue before publishing.

We do not run a paid bug bounty. There is no reward beyond our thanks and credit if you want it, and we would rather say so plainly than imply one.

Sub-processors

9 third parties process customer data on our behalf.

See the full listRead the DPA