Built for regulators, not retrofitted for them.
Trelice handles the documents that define how patients are treated. We build the platform to the standard the regulator expects, because anything less isn’t real.
Regulatory standards
Infrastructure
Security practices
Encryption
AES-256 at rest, TLS 1.3 in transit. Customer data encrypted with per-tenant keys.
Access control
SSO via SAML / OIDC. Role-based access at document and field level. Session binding.
Audit trail
Every read, write, and approval event logged, immutable, and exportable. Architected to support 21 CFR Part 11 requirements; validation in progress.
Backup & continuity
Point-in-time recovery to any second in the last 35 days. Multi-region standby on Enterprise.
Vulnerability management
Annual pen test by an independent third party. Continuous dependency scanning. 48-hour critical patch SLO.
Data residency
US or EU at standard tier. APAC on Enterprise. No cross-region replication without written consent.
Responsible disclosure
Found a vulnerability? Email security@trelice.com. We aim to acknowledge within one business day and resolve critical issues within 7 days. We run a private bug-bounty programme; contact us for scope.