Trellis Data

trellisdata.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
43 / 100D
Procurement decision
Approve with conditions
2 conditions outstanding
  • No formal subprocessor register disclosed
  • No independent assurance evidenced

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification None

Scanned Aug 31, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No independent assurance evidencedCondition

Why it matters: No SOC 2 Type II, ISO/IEC 42001, or registry-verified certification covering the AI product was found in the public sources scanned.

What to ask for: Request a SOC 2 Type II or ISO/IEC 42001 report and confirm its scope covers the AI product.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Trellis Data states in its licence agreement that it does not use customer data to develop its products or train its AI, explicitly contrasting itself with platforms that do, and commits not to access prompts, created content, AI decisions or documents except at the customer's request.

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.
How long do they keep your data?Clear

Validation documentation is not retained beyond the period reasonably required to complete validation, and is securely destroyed or returned on completion or request.

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law. 25.4. Upon completion of the validation phase, or upon request, Trellis Data will securely destroy or return all copies of Validation Documentation
the Personal Information provided is no longer necessary in relation to the purpose of collection; (b) you have withdrawn your consent for us to hold your Personal Information; (c) the legal retention period for holding your Personal Information has expired; (d) you object to the use of your Personal Information; or (e) the processing of your Personal Information was not in accordance with the EU GDPR.
!Who else can access your data?Ask the vendor

Trellis Data states the AI models themselves sit in Australian secured data centres alongside the data, indicating self-hosted models rather than calls out to a third-party model provider. No third-party model provider is named anywhere in the sources scanned.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.
!Where is your data processed?Ask the vendor

Trellis Data states that Agentaus holds both the AI models and customer data in Australian secured data centres, that data never leaves Australia, and that it will not view, commercialise or use customer data for AI training.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.
!What happens in a security incident?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Confirm in writing: Ask the vendor to state this in writing before signing.

Key findingsclick a row for the evidence

An unusually direct commitment not to train on customer dataStrong

The licence agreement states plainly that Trellis Data does not use customer data to develop its products or train its AI, naming the practice it is distinguishing itself from, and commits not to access prompts, created content, AI decisions or documents except on request.

This sits in the licence agreement rather than a marketing page, so it is contractually binding rather than a statement of intent. It is more specific than most vendors offer — it enumerates what will not be accessed rather than relying on a general assurance.

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.
Sovereign hosting with an air-gapped deployment optionStrong

Agentaus holds models and data in Australian data centres with data stated never to leave Australia, and the platform can be deployed on-premises fully disconnected from the internet.

For Australian government and regulated buyers, in-country processing plus a genuinely disconnected deployment answers sovereignty and classification questions that most global AI vendors cannot. It is the strongest thing in this vendor's public evidence.

Question for vendor: Which Australian data centre regions are used, and what is the supported configuration for the disconnected deployment?

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Also available as a fully deployable solution on-prem and even disconnected from the internet. Have access to leading AI and AI collaboration on your own high security network.
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.
!No independent assurance is evidenced anywhere in publicGap

No certification, attestation or third-party audit report was found in any source scanned — no ISO/IEC 27001, no SOC 2, no IRAP assessment, and no trust or compliance page carrying them.

Every commitment above is the vendor's own word. For a vendor positioning on defence-grade sovereignty, the absence of an independent assessment is the gap that most limits how far a buyer can rely on the claims without their own due diligence. It is an absence of evidence, not evidence of absence — the certifications may exist and simply not be published.

Question for vendor: Do you hold ISO/IEC 27001, SOC 2 or an IRAP assessment, and can you provide the certificate or report with its scope statement?

Evidence
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.
!No subprocessor register is publishedGap

No list of subprocessors or third-party service providers was found. The sources indicate models are self-hosted in Australia, which would reduce the subprocessor surface, but nothing states who else may process customer data.

Self-hosted models genuinely narrow the supply chain compared with a vendor routing to a third-party LLM, so the exposure here is likely smaller than average. But a buyer cannot verify that without a register, and cannot be notified when it changes.

Question for vendor: Can you provide a list of subprocessors with processing locations, and confirm whether any customer content reaches a third-party model provider?

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.
!Incident response and change management are not addressed publiclyGap

Nothing in the scanned sources covers security incident handling, breach notification timelines, vulnerability disclosure, or how model and service changes are communicated to customers.

These are standard contract schedule items. Their absence from public material does not mean they are absent from a negotiated agreement, but they cannot be assessed from outside and should be asked for directly.

Question for vendor: What are your breach notification timeframes, and how are customers notified of model or service changes?

Evidence
This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the EU GDPR).
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
Trellis Data may conduct audits to ensure compliance with the terms and conditions of this Agreement. You agree to cooperate with these audits and provide reasonable assistance and information as requested by Trellis Data.
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
Trellis Data may conduct audits to ensure compliance with the terms and conditions of this Agreement. You agree to cooperate with these audits and provide reasonable assistance and information as requested by Trellis Data.
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You acknowledge that Trellis Data is not responsible for ensuring your compliance with these laws and regulations.
AI system15% of the score20
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Also available as a fully deployable solution on-prem and even disconnected from the internet. Have access to leading AI and AI collaboration on your own high security network.
On-Premises Deployment Deploy the Trellis Intelligence Platform on a dedicated server stack inside your organization’s own data center. Private Cloud Deployment Deploy the Trellis Intelligence Platform on a private cloud infrastructure hosted by Trellis Data, providing a secure and isolated environment for your data and AI
In situations where every second counts, and internet connectivity is unreliable or non-existent, the DMATS (Decision Making at the Edge) solution provides a rugged, portable, and powerful AI computing platform.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.
Customer data15% of the score60
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law. 25.4. Upon completion of the validation phase, or upon request, Trellis Data will securely destroy or return all copies of Validation Documentation
the Personal Information provided is no longer necessary in relation to the purpose of collection; (b) you have withdrawn your consent for us to hold your Personal Information; (c) the legal retention period for holding your Personal Information has expired; (d) you object to the use of your Personal Information; or (e) the processing of your Personal Information was not in accordance with the EU GDPR.

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedMaster your knowledge — Trellis Dataretrieved Aug 31, 2026
Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.
Security foundation15% of the score0
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Not Evidenced

Vulnerability & incident handling: not publicly evidenced.

Independent assurance evidence10% of the score0
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Not Evidenced

Independent assurance: not publicly evidenced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the EU GDPR).
Vendor publishedTerms of Service — Trellis Dataretrieved Aug 31, 2026
You acknowledge that Trellis Data is not responsible for ensuring your compliance with these laws and regulations.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+4Publish Change management evidenceAI System 2040
+4Complete the Governance & accountability disclosureOrganisation 4060
+4Publish Testing & evaluation evidenceAI System 2040
+4Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 059
+3Have Customer data treatment disclosures independently corroboratedData 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 43 → up to 66 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESTrellis DataTrellis DataAgentausAgentaus
View as list
Trellis Data Uses AI Service Agentaus

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 1 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Sources 12 — click to view
Master your knowledge — Trellis Data
AI Documentation · Vendor · retrieved Aug 31, 2026
Privacy Policy | Learn More About Privacy — Trellis Data
Privacy Notice · Vendor · retrieved Aug 31, 2026
Terms of Service — Trellis Data
Terms · Vendor · retrieved Aug 31, 2026
Deployment | Learn More and Deploy Today — Trellis Data
AI Documentation · Vendor · retrieved Aug 31, 2026
https://agentaus.com.au/eng/privacy
Privacy Notice · Vendor · retrieved Aug 31, 2026
AI at the Edge | Discover Edge AI Solutions — Trellis Data
AI Documentation · Vendor · retrieved Aug 31, 2026
Our Platform | Discover AI Solutions Today — Trellis Data
AI Documentation · Vendor · retrieved Aug 31, 2026
Trellis Data releases Agentaus — Trellis Data
AI Documentation · Vendor · retrieved Aug 31, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
ISO/IEC 27017:2026Published (2015 edition withdrawn)
Cloud information security controls · Second edition, restructured to the 27002:2022 taxonomy — cloud/SaaS assurance work citing 27017 should reference this edition. Vault holds the 2015 extraction; 2026 not acquired by decision. Verified via ISO catalogue read 2026-08-18.

Want to go further?

This scan assesses Trellis Data at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.