Where the case data lives.
Stage disclosure. Trustee OS is an early product in customer discovery. There is no production deployment, no client tenancy, no software in commercial use, and no formal security programme, certification or third-party audit in force. Nothing on this page describes an implemented or verified control. This website and the clickable prototype contain no real client data — the prototype is synthetic, non-production and not connected to any court.
An insolvency file is not ordinary business data. It carries the debtor's books, creditor identities and amounts that are not public until the court says they are. Any administrator evaluating an early product should ask what it would do with that material before there is any material to hold. Here is what we intend to build, stated as intent.
Case isolation is an architectural requirement: the architecture is designed so one administrator's file would not be queryable from another's session, with the boundary enforced in the database and not only in the application. That is a design requirement under build, not a property of any deployed system.
The intended design encrypts data in transit and at rest, authenticates access per user, and records who read or changed what and when. That record is specified because an administrator has to be able to account to the court — but it is a specification, not something we have operated at scale.
Data residency is intended to follow the case. A Brazilian recuperação judicial would not need to leave Brazil, and we would host it accordingly. No hosting arrangement for client data exists today.
We would sign a confidentiality agreement before you send us anything, and we do not need production data for a design conversation — a redacted or synthetic set is enough to test whether the claims logic reconciles correctly.
If you want the technical detail before a first conversation, write to info@trusteeos.ai and ask. You will get a straight answer, including where we are not yet where we want to be.