Trellis Data
trellisdata.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No formal subprocessor register disclosed
- No independent assurance evidenced
See Before you sign, with what to ask for ↓
Scanned Aug 31, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: No SOC 2 Type II, ISO/IEC 42001, or registry-verified certification covering the AI product was found in the public sources scanned.
What to ask for: Request a SOC 2 Type II or ISO/IEC 42001 report and confirm its scope covers the AI product.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Trellis Data states in its licence agreement that it does not use customer data to develop its products or train its AI, explicitly contrasting itself with platforms that do, and commits not to access prompts, created content, AI decisions or documents except at the customer's request.
“You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.”
✓How long do they keep your data?Clear
Validation documentation is not retained beyond the period reasonably required to complete validation, and is securely destroyed or returned on completion or request.
“Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law. 25.4. Upon completion of the validation phase, or upon request, Trellis Data will securely destroy or return all copies of Validation Documentation”
“the Personal Information provided is no longer necessary in relation to the purpose of collection; (b) you have withdrawn your consent for us to hold your Personal Information; (c) the legal retention period for holding your Personal Information has expired; (d) you object to the use of your Personal Information; or (e) the processing of your Personal Information was not in accordance with the EU GDPR.”
!Who else can access your data?Ask the vendor
Trellis Data states the AI models themselves sit in Australian secured data centres alongside the data, indicating self-hosted models rather than calls out to a third-party model provider. No third-party model provider is named anywhere in the sources scanned.
Requires written confirmation — see Before you sign ↓
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
!Where is your data processed?Ask the vendor
Trellis Data states that Agentaus holds both the AI models and customer data in Australian secured data centres, that data never leaves Australia, and that it will not view, commercialise or use customer data for AI training.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.”
!What happens in a security incident?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
Confirm in writing: Ask the vendor to state this in writing before signing.
Key findingsclick a row for the evidence
✓An unusually direct commitment not to train on customer dataStrong
The licence agreement states plainly that Trellis Data does not use customer data to develop its products or train its AI, naming the practice it is distinguishing itself from, and commits not to access prompts, created content, AI decisions or documents except on request.
This sits in the licence agreement rather than a marketing page, so it is contractually binding rather than a statement of intent. It is more specific than most vendors offer — it enumerates what will not be accessed rather than relying on a general assurance.
“You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.”
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.”
✓Sovereign hosting with an air-gapped deployment optionStrong
Agentaus holds models and data in Australian data centres with data stated never to leave Australia, and the platform can be deployed on-premises fully disconnected from the internet.
For Australian government and regulated buyers, in-country processing plus a genuinely disconnected deployment answers sovereignty and classification questions that most global AI vendors cannot. It is the strongest thing in this vendor's public evidence.
Question for vendor: Which Australian data centre regions are used, and what is the supported configuration for the disconnected deployment?
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.”
“Also available as a fully deployable solution on-prem and even disconnected from the internet. Have access to leading AI and AI collaboration on your own high security network.”
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
!No independent assurance is evidenced anywhere in publicGap
No certification, attestation or third-party audit report was found in any source scanned — no ISO/IEC 27001, no SOC 2, no IRAP assessment, and no trust or compliance page carrying them.
Every commitment above is the vendor's own word. For a vendor positioning on defence-grade sovereignty, the absence of an independent assessment is the gap that most limits how far a buyer can rely on the claims without their own due diligence. It is an absence of evidence, not evidence of absence — the certifications may exist and simply not be published.
Question for vendor: Do you hold ISO/IEC 27001, SOC 2 or an IRAP assessment, and can you provide the certificate or report with its scope statement?
“You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.”
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.”
!No subprocessor register is publishedGap
No list of subprocessors or third-party service providers was found. The sources indicate models are self-hosted in Australia, which would reduce the subprocessor surface, but nothing states who else may process customer data.
Self-hosted models genuinely narrow the supply chain compared with a vendor routing to a third-party LLM, so the exposure here is likely smaller than average. But a buyer cannot verify that without a register, and cannot be notified when it changes.
Question for vendor: Can you provide a list of subprocessors with processing locations, and confirm whether any customer content reaches a third-party model provider?
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
!Incident response and change management are not addressed publiclyGap
Nothing in the scanned sources covers security incident handling, breach notification timelines, vulnerability disclosure, or how model and service changes are communicated to customers.
These are standard contract schedule items. Their absence from public material does not mean they are absent from a negotiated agreement, but they cannot be assessed from outside and should be asked for directly.
Question for vendor: What are your breach notification timeframes, and how are customers notified of model or service changes?
“This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the EU GDPR).”
“Trellis Data may conduct audits to ensure compliance with the terms and conditions of this Agreement. You agree to cooperate with these audits and provide reasonable assistance and information as requested by Trellis Data.”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score40
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Trellis Data may conduct audits to ensure compliance with the terms and conditions of this Agreement. You agree to cooperate with these audits and provide reasonable assistance and information as requested by Trellis Data.”
“You acknowledge that Trellis Data is not responsible for ensuring your compliance with these laws and regulations.”
AI system15% of the score20
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Also available as a fully deployable solution on-prem and even disconnected from the internet. Have access to leading AI and AI collaboration on your own high security network.”
“On-Premises Deployment Deploy the Trellis Intelligence Platform on a dedicated server stack inside your organization’s own data center. Private Cloud Deployment Deploy the Trellis Intelligence Platform on a private cloud infrastructure hosted by Trellis Data, providing a secure and isolated environment for your data and AI”
“In situations where every second counts, and internet connectivity is unreliable or non-existent, the DMATS (Decision Making at the Edge) solution provides a rugged, portable, and powerful AI computing platform.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the score40
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
Customer data15% of the score60
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“You use our data. We do not use your data. Many artificial intelligence (AI) platforms use your data to further develop their products, including training their AI systems. We do not use your data, you use ours. The only time we access, view or use your data is when you request us to.”
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country. We also guarantee to not view, commercialise or use your data for AI training - ensuring that you have complete sovereign ownership of your data and what Agentaus produces for you.”
“Trellis Data will not use Validation Documentation for any purpose other than as set out in this clause, nor retain the documentation beyond the period reasonably required to complete validation, unless otherwise required by law. 25.4. Upon completion of the validation phase, or upon request, Trellis Data will securely destroy or return all copies of Validation Documentation”
“the Personal Information provided is no longer necessary in relation to the purpose of collection; (b) you have withdrawn your consent for us to hold your Personal Information; (c) the legal retention period for holding your Personal Information has expired; (d) you object to the use of your Personal Information; or (e) the processing of your Personal Information was not in accordance with the EU GDPR.”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score40
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Agentaus has the AI models, and data completely in Australian secured data centres. This means your data never leaves Australia and the AI is also in-country.”
Security foundation15% of the score0
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the score0
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
Independent assurance: not publicly evidenced.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the EU GDPR).”
“You acknowledge that Trellis Data is not responsible for ensuring your compliance with these laws and regulations.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 43 → up to 66 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 1 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Sources 12 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Trellis Data at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
