Skip to content

Security & trust

Customer trust is the product. We build like it.

Trestelo handles your customers' conversations and contact details. This page describes the protections that are architecturally real today — not aspirations.

Isolation per business

Each business runs in its own isolated data space within our multi-tenant architecture. Customer data never crosses between businesses — isolation is enforced at the data layer, not by filters.

Role-based access control

Every team member acts under a role with defined permissions, enforced on the server for every request — the dashboard hides what you cannot do, and the API refuses it too.

Controlled knowledge sources

Live AI answers use only knowledge your team has reviewed and published. Drafts are never served, releases are versioned, and rollback is immediate.

Audited sensitive actions

Publishing knowledge, changing integrations, role changes, support access, exports — sensitive operations write an audit record with who, what, and when.

Data protection

Channel credentials and secrets are encrypted at rest. Sensitive fields like phone numbers are masked in logs. Webhooks are signature-verified before processing.

Human handover built in

Automation always has an exit. Escalation rules, approval points, and conversation review keep people in control of customer-facing behavior.

Configurable retention

Retention policies per data type, with legal-hold support and scheduled, auditable pruning — not a manual cleanup ritual.

Scoped platform support access

When our support staff need access to help you, it is requested, scoped, time-limited, PII-masked by default, and fully audited — visible to you.

We do not currently hold formal certifications such as SOC 2 or ISO 27001, and we won’t imply otherwise with badges. If your procurement process has specific security requirements, contact us — we’ll answer questionnaires directly and honestly.

Security questions

Where does our data live?

In your business’s own isolated data space within Trestelo’s infrastructure. Exports are available so your systems of record stay current, and deletion follows a documented process.

Can Trestelo staff read our conversations?

Not by default. Support access is requested per case, scoped, time-limited, masked for personal data unless explicitly widened, and every access is audited.

How do you prevent the AI from making things up?

Live answers are grounded in your reviewed, published knowledge. When the answer isn’t there, the AI says so and follows your fallback rule — typically handing over to your team.

How is customer consent handled?

Consent for follow-up, data sharing, and marketing is tracked per contact, auditable, and reversible — and outbound messaging respects platform policy windows automatically.

Have a security questionnaire?

Send it over — we answer directly, including the questions where the honest answer is 'on the roadmap'.