FillTrust

FillTrust's own page, rendered by the same component your Trust Center uses.

How yours works

Trust Center

FillTrust’s security posture

Answers to the questions we are asked most often, published so you do not have to send a questionnaire to get them.

11
questions answered here
3
documents on file
30 Aug 2026
last reviewed
None held
independent audit reports

Questions we are asked most often

Is customer data encrypted in transit and at rest?
Yes. Everything is encrypted in transit with TLS and at rest by Google Cloud. TOTP secrets are additionally encrypted at the application layer with AES-256-GCM, so a database read alone does not yield a working second factor.
How is one customer's data kept separate from another's?
Every API request derives its tenant from the authenticated session, server-side. No endpoint accepts a customer identifier from the browser, and a request for another tenant's data returns 404 rather than confirming the record exists.
Where is customer data stored?
Documents are stored in Google Cloud in Paris and the database is hosted in Frankfurt, both of them in the EU. Question text and the specific excerpts used to answer are sent to AI providers in the United States under Standard Contractual Clauses. Neither provider trains on API data.
Do you train models on customer data?
No. We call Google and OpenAI through their standard business APIs, whose terms exclude API content from training. To be precise about what that does and does not mean: it is a contractual commitment not to train on your content, and providers may still retain it briefly for abuse monitoring under their own published policies. We do not hold a zero-retention agreement with either provider, and we would rather say so than imply a guarantee we have not bought.
Do you maintain a current SOC 2 Type II report?
No. FillTrust does not hold a SOC 2 report or an ISO 27001 certificate. This page and our security documentation are what we have instead, and we would rather publish that plainly than let the question go unanswered. If certification is a requirement for you, tell us. It is the kind of thing that changes a roadmap.
Do you delete customer data on request?
Yes. Deleting your account cancels billing, removes every uploaded document and generated questionnaire from storage, and deletes your records. If any part of that cannot be completed the deletion is aborted and reported rather than partially applied.
Do you maintain a sub-processor list, and will you sign a DPA?
Yes to both. The current sub-processor list and our Data Processing Agreement, including the Standard Contractual Clauses, are published rather than sent on request. You should not have to ask for either.
Is multi-factor authentication available?
Yes. Accounts are protected by a password with optional TOTP two-factor authentication, and authentication endpoints are rate limited. Enforced SSO is not currently supported.
Can you show who changed an answer, and when?
Yes. Every answer change is recorded: what it was, what it became, who changed it and when. That includes answers submitted by outside experts through a review link. Generated answers cite the passages they were drawn from, and a citation that cannot be verified against the source lowers the answer's grade rather than being published.
How do you handle reported vulnerabilities?
There is a published disclosure policy on our security page and a security.txt at the standard location, both naming a contact that reaches a person. It commits to acknowledging a report within five working days and offers safe harbour for good-faith research within a stated scope. We do not run a paid bug bounty and say so rather than implying one.
What is your incident notification commitment?
The commitment in our DPA governs, and it is the document to hold us to. Operationally, uptime is checked continuously, backend errors raise an alert, and object storage is versioned so an accidental overwrite is recoverable.

Documentation

There is no SOC 2 report or ISO 27001 certificate to share under NDA, because we do not hold one. Everything we do have is on this page or linked from it, which is why none of it needs requesting.

The same answers, for machines

Most vendor reviews now begin with a tool rather than a person, and it reads whatever the domain exposes before anyone here knows an evaluation started. These are the answers above in the formats that tool understands, generated from the same source as this page, so they cannot disagree with it.