Back to home

Security Overview

Last updated: 24 July 2026

This page describes the current production setup of TrustRespond.ai. It is an operational overview, not a certification or an assurance report. Contract-specific controls are documented separately in the applicable order form and DPA.

1. Hosting and data location

ServiceProviderCurrent regionPurpose
Web application and server functionsVercelFrankfurt, Germany (fra1)Application delivery and request processing
Database, authentication and storageSupabaseCentral EU, Frankfurt (eu-central-1)Customer data, access and files
AI inferenceGoogle Gemini APIProvider-managed processingGemini 2.5 Flash answer suggestions
Transactional emailZoho Mail SMTPProvider-managed processingPilot and operational email

EU hosting of the application and primary database does not by itself mean that every subprocessor operation is confined to the EEA. International transfers and safeguards are described in the Privacy Policy.

2. Access control and tenant separation

Access is authenticated and application data is scoped to the relevant workspace. Privileged administrative access is restricted to authorised operators. Database policies and server-side checks are used to prevent one customer from accessing another customer's records. Customers should still avoid uploading material that is not required for the agreed questionnaire workflow.

3. Transport and secrets

Public application traffic is served over HTTPS. Service credentials and API keys are held in deployment environment configuration and are not exposed in the browser. Security-sensitive changes are reviewed through the repository and deployment workflow.

4. Retention and deletion

DataCurrent retention
Uploaded documents and generated questionnaire results90 days, unless an earlier deletion is requested or contractually agreed
Pilot and sales leadsRetained until manually deleted or a valid erasure request is fulfilled; no fixed automatic expiry currently applies
Short-lived abuse-prevention keysPruned after the active rate-limit window; raw IP addresses are not stored in the lead database

Deletion requests can be sent to info@trustrespond.ai.

5. Backup and recovery

TrustRespond.ai does not currently operate a separate automated application backup process. Provider-level resilience must not be treated as a customer-restorable backup commitment. Customers should retain authoritative copies of source documents and exported results. Any contractual backup or recovery requirement must be agreed before a production project.

6. Incident handling

Suspected security incidents are assessed, contained and documented by the operator. Affected customers are notified without undue delay where required by law or contract. Security reports can be sent to info@trustrespond.ai; include reproduction steps and avoid sending confidential documents by ordinary email.

7. AI processing and human approval

The current hosted workflow uses Google Gemini 2.5 Flash to generate answer suggestions from customer-provided context. Outputs can be incomplete or incorrect and require human review before export or external use. TrustRespond.ai does not use customer documents to train its own public model. Provider processing is governed by the applicable provider terms and the customer agreement. See AI system information.

8. Deployment options: current versus available by project

TermStatusMeaning
EU-hosted SaaSCurrent production optionVercel and Supabase production resources are configured in Frankfurt.
Private deploymentProject-specificA separately scoped environment may be designed and priced after technical review.
BYOKNot implementedCustomers cannot currently supply their own model API key in the hosted product.
On-premise-ready architectureDesign direction, not a packaged featureArchitecture may be adapted during an enterprise project; this is not a claim that the hosted product can be self-installed today.
On-premise deploymentSeparate engineering projectRequires agreed infrastructure, model, operations, support and security responsibilities.

9. Assurance boundaries

TrustRespond.ai does not currently claim SOC 2, ISO 27001 or TISAX certification and does not publish a guaranteed SLA. The product supports preparation and review workflows; it does not certify a customer's compliance.