Security

What goes in stays yours.

How Truss handles what a firm and its witnesses put into the service.

Last updated September 29, 2026. The Terms of Service govern; this page says what happens in practice.

Outside Truss

Your content trains nothing.

Truss does not use customer content to train AI models. Neither do the two AI providers it runs on: every request to OpenAI is sent marked not to be stored, and Tavus has zero data retention switched on for Truss's account.

OpenAI

The examiner's questions, the second chair, the session report, and document processing.

Receives

The transcript, the case background, the strategy notes, the examination plan, the text of documents, and the page images of a scanned document.

Never gets

The recording, or the witness's voice and video.

Stores

Nothing. Zero data retention: every request is marked not to be stored, and none of it trains a model.

Tavus

The examiner's voice and face, in the video call.

Receives

The witness's audio and video during the session, and the examiner's spoken questions, which can quote an exhibit.

Never gets

The case materials, the notes, and the plan.

Stores

Nothing. Zero data retention on Truss's account; the recording goes straight into Truss's own storage.

Beyond those two, Stripe sees the billing email and the names on each invoice line (the witness, the matter, and who created the session link), and Resend sees the email addresses sign-in links and invitations go to. No case content reaches either.

Where it lives

In the United States, one firm apart from the next.

Recordings sit in a private Amazon S3 bucket; everything else is in a Supabase database and storage. Both are in the United States and encrypted in transit and at rest. The web app runs on Vercel and the api on Railway, and neither stores customer content.

Each firm's content is kept apart from every other firm's, and only the people a firm invites can open its matters. Signing in is a one-time emailed link, so there are no passwords to lose; a witness joins from a private link with no account.

Truss's staff can access customer content to operate, secure, and support the service, or when the customer asks, and for nothing else.

How long it stays

Gone on a date you set, or when you say.

Session recordings
Deleted on the recording's deletion date: 30 days after it lands by default, up to 365 by a matter's setting. The session page can move the date, or clear it to keep the recording until the session is deleted.
Camera measurements
Taken only when the witness agrees. They and the observations made from them are deleted 80 days after the session.
Transcripts, reports, documents, notes
Stay until the customer deletes them or the agreement ends.
Operational logs
Hold timing and counts, never what was said. Model output kept for troubleshooting is cleared after 7 days.
The witness's consent record
Stays after the session is deleted. It holds no name and no content.
After a delete
Gone from every copy Truss controls within 7 days, which is how long the database's backups are kept.
Questions and incidents

Within 72 hours.

If Truss learns of an incident affecting a customer's content, it notifies the customer within 72 hours. Anything this page leaves open, and any vulnerability report, goes to privacy@trusslegal.com.