Trellis Data

trellisdata.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
38 / 100F
Procurement decision
Approve with conditions
3 conditions outstanding
  • No formal subprocessor register disclosed
  • Data retention window not stated
  • No independent assurance evidenced

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification None

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law.
Personal Information held by us is retained until: (a) such time as we deem this Personal Information to no longer be active, timely or correct (Inactive Personal Information);
No independent assurance evidencedCondition

Why it matters: No SOC 2 Type II, ISO/IEC 42001, or registry-verified certification covering the AI product was found in the public sources scanned.

What to ask for: Request a SOC 2 Type II or ISO/IEC 42001 report and confirm its scope covers the AI product.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

The user agreement commits that Trellis does not use customer data: no access to prompts, created content, AI decisions or documents for any unagreed purpose, expressly including AI training, data collection or reselling.

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
We do not use your data, you use ours. The only time we access, view or use your data is when you request us to. Specifically, we will not access prompts, content created, AI decisions made, documents or other customer data used for any purpose you do not expressly agree to, including AI training, data collection, reselling, or any other form of data
!How long do they keep your data?Ask the vendor

Validation documentation is used only for validation, not retained beyond the reasonable period, and securely destroyed or returned on completion.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law.
Personal Information held by us is retained until: (a) such time as we deem this Personal Information to no longer be active, timely or correct (Inactive Personal Information);
!Who else can access your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!Where is your data processed?Ask the vendor

Agentaus commits that data never leaves Australia, the AI runs in-country, and customer data is not viewed, commercialised or used for AI training.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 28, 2026
your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data
!What happens in a security incident?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Confirm in writing: Ask the vendor to state this in writing before signing.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
Trellis Data may conduct audits to ensure compliance with the terms and conditions of this Agreement. You agree to cooperate with these audits and provide reasonable assistance and information as requested by Trellis Data.
AI system15% of the score20
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Deploy the Trellis Intelligence Platform on a private cloud infrastructure hosted by Trellis Data, providing a secure and isolated environment for your data and AI processing. Public Cloud Deployment Amazon Web Services Microsoft Azure Google Cloud Platform
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Deploy the Trellis Intelligence Platform on a private cloud infrastructure hosted by Trellis Data, providing a secure and isolated environment for your data and AI processing. Public Cloud Deployment Amazon Web Services Microsoft Azure Google Cloud Platform
Customer data15% of the score60
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
We do not use your data, you use ours. The only time we access, view or use your data is when you request us to. Specifically, we will not access prompts, content created, AI decisions made, documents or other customer data used for any purpose you do not expressly agree to, including AI training, data collection, reselling, or any other form of data
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 28, 2026
your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law.
Personal Information held by us is retained until: (a) such time as we deem this Personal Information to no longer be active, timely or correct (Inactive Personal Information);

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Security foundation15% of the score40
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Independent assurance evidence10% of the score0
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Not Evidenced

Independent assurance: not publicly evidenced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 28, 2026
We do not use your data, you use ours. The only time we access, view or use your data is when you request us to. Specifically, we will not access prompts, content created, AI decisions made, documents or other customer data used for any purpose you do not expressly agree to, including AI training, data collection, reselling, or any other form of data
This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the EU GDPR).

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+8Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 059
+3Publish Change management evidenceAI System 2040
+3Complete the Governance & accountability disclosureOrganisation 4060
+3Publish Testing & evaluation evidenceAI System 2040
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 4060

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 38 → up to 66 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESINFRASTRUCTURETrellis DataTrellis DataAgentaus (formerly Trellis Secure Chat)Agentaus (formerly Trelli…Trellis Intelligence Platform (TIP)Trellis Intelligence Plat…DMATS (Decision Making at the Edge)DMATS (Decision Making at…Facial recognition and gait analysisFacial recognition and ga…Amazon Web Services (customer-selectable deployment)Amazon Web Services (cust…Microsoft Azure (customer-selectable deployment)Microsoft Azure (customer…Google Cloud Platform (customer-selectable deployment)Google Cloud Platform (cu…Trellis Data hosted private cloudTrellis Data hosted priva…NVIDIA Jetson Nano (edge hardware)NVIDIA Jetson Nano (edge …

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 1 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Sources 12 — click to view
Master your knowledge — Trellis Data
AI Documentation · Vendor · retrieved Aug 28, 2026
Privacy Policy | Learn More About Privacy — Trellis Data
Privacy Notice · Vendor · retrieved Aug 28, 2026
Terms of Service — Trellis Data
Terms · Vendor · retrieved Aug 28, 2026
Deployment | Learn More and Deploy Today — Trellis Data
AI Documentation · Vendor · retrieved Aug 28, 2026
https://agentaus.com.au/eng/privacy
Privacy Notice · Vendor · retrieved Aug 28, 2026
AI at the Edge | Discover Edge AI Solutions — Trellis Data
AI Documentation · Vendor · retrieved Aug 28, 2026
Our Platform | Discover AI Solutions Today — Trellis Data
AI Documentation · Vendor · retrieved Aug 28, 2026
Trellis Data releases Agentaus — Trellis Data
AI Documentation · Vendor · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
ISO/IEC 27017:2026Published (2015 edition withdrawn)
Cloud information security controls · Second edition, restructured to the 27002:2022 taxonomy — cloud/SaaS assurance work citing 27017 should reference this edition. Vault holds the 2015 extraction; 2026 not acquired by decision. Verified via ISO catalogue read 2026-08-18.

Want to go further?

This scan assesses Trellis Data at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.