This page describes the current production setup of TrustRespond.ai. It is an operational overview, not a certification or an assurance report. Contract-specific controls are documented separately in the applicable order form and DPA.
1. Hosting and data location
| Service | Provider | Current region | Purpose |
|---|---|---|---|
| Web application and server functions | Vercel | Frankfurt, Germany (fra1) | Application delivery and request processing |
| Database, authentication and storage | Supabase | Central EU, Frankfurt (eu-central-1) | Customer data, access and files |
| AI inference | Google Gemini API | Provider-managed processing | Gemini 2.5 Flash answer suggestions |
| Transactional email | Zoho Mail SMTP | Provider-managed processing | Pilot and operational email |
EU hosting of the application and primary database does not by itself mean that every subprocessor operation is confined to the EEA. International transfers and safeguards are described in the Privacy Policy.
2. Access control and tenant separation
Access is authenticated and application data is scoped to the relevant workspace. Privileged administrative access is restricted to authorised operators. Database policies and server-side checks are used to prevent one customer from accessing another customer's records. Customers should still avoid uploading material that is not required for the agreed questionnaire workflow.
3. Transport and secrets
Public application traffic is served over HTTPS. Service credentials and API keys are held in deployment environment configuration and are not exposed in the browser. Security-sensitive changes are reviewed through the repository and deployment workflow.
4. Retention and deletion
| Data | Current retention |
|---|---|
| Uploaded documents and generated questionnaire results | 90 days, unless an earlier deletion is requested or contractually agreed |
| Pilot and sales leads | Retained until manually deleted or a valid erasure request is fulfilled; no fixed automatic expiry currently applies |
| Short-lived abuse-prevention keys | Pruned after the active rate-limit window; raw IP addresses are not stored in the lead database |
Deletion requests can be sent to info@trustrespond.ai.
5. Backup and recovery
TrustRespond.ai does not currently operate a separate automated application backup process. Provider-level resilience must not be treated as a customer-restorable backup commitment. Customers should retain authoritative copies of source documents and exported results. Any contractual backup or recovery requirement must be agreed before a production project.
6. Incident handling
Suspected security incidents are assessed, contained and documented by the operator. Affected customers are notified without undue delay where required by law or contract. Security reports can be sent to info@trustrespond.ai; include reproduction steps and avoid sending confidential documents by ordinary email.
7. AI processing and human approval
The current hosted workflow uses Google Gemini 2.5 Flash to generate answer suggestions from customer-provided context. Outputs can be incomplete or incorrect and require human review before export or external use. TrustRespond.ai does not use customer documents to train its own public model. Provider processing is governed by the applicable provider terms and the customer agreement. See AI system information.
8. Deployment options: current versus available by project
| Term | Status | Meaning |
|---|---|---|
| EU-hosted SaaS | Current production option | Vercel and Supabase production resources are configured in Frankfurt. |
| Private deployment | Project-specific | A separately scoped environment may be designed and priced after technical review. |
| BYOK | Not implemented | Customers cannot currently supply their own model API key in the hosted product. |
| On-premise-ready architecture | Design direction, not a packaged feature | Architecture may be adapted during an enterprise project; this is not a claim that the hosted product can be self-installed today. |
| On-premise deployment | Separate engineering project | Requires agreed infrastructure, model, operations, support and security responsibilities. |
9. Assurance boundaries
TrustRespond.ai does not currently claim SOC 2, ISO 27001 or TISAX certification and does not publish a guaranteed SLA. The product supports preparation and review workflows; it does not certify a customer's compliance.