Who we are
Trellis™ is a Hortiki Innovations initiative of Hortiki Plants LLC, a Maryland limited liability company. Contact: info@trelliscompliance.co.
What we collect
| Data | Why | Who can see it |
|---|---|---|
| Names and work emails of clients, experts, and admin who sign in | Access, magic-link login, routing work | Hortiki admin; the account holder |
| Quote / invoice buyer details, PO numbers, tax-exemption notes | Billing and procurement | Hortiki admin; the buyer contact |
| Lab files (CoAs, chemical/sequence uploads), intake answers, dossier drafts, Q&A, verification audio | Deliver the fixed-scope sprint | Client on the engagement; assigned expert; Hortiki admin for QC |
| Structured CoA extraction JSON and confidence flags | Pre-fill templates; highlight review fields | Same as engagement files |
| Payment status from Stripe (when live); Wise email/tag for experts | Confirm payment; pay experts | Hortiki admin; expert sees own Wise profile |
What we do not do
- We do not sell personal information or client laboratory files.
- We do not store full payment card numbers (Stripe handles cards).
- We do not store expert bank account numbers (Wise email/tag only).
- We do not use advertising pixels on the Trellis site by default.
- Experts cannot browse other clients’ engagements — only sprints assigned to them.
Where it lives and how it is protected
Trellis runs on Cloudflare Pages and Functions with D1 (structured data), R2 (file vault trellis-vault), and KV (config / rate limits). Traffic uses HTTPS/TLS. Cloudflare’s documentation states D1 data is encrypted at rest with AES-256 and that D1 is covered by Cloudflare’s SOC 2 and ISO 27001 certifications. Hortiki Plants LLC itself does not hold SOC 2 or ISO 27001 certification. Sign-in is by email magic link and a session cookie.
AI
CoA extraction may use heuristics plus optional Cloudflare Workers AI to help fill fields. Document text is processed to deliver the engagement. Low-confidence fields are flagged for human review. We do not use client files to train a public model.
How long we keep it
Engagement files remain available through delivery and any included revision window. Default working retention after close is about 90 days unless your order form or MSA says otherwise, then deletion from the working vault except records law requires us to keep (invoices, acknowledgments). Server logs are short-lived (typically up to 7 days on Cloudflare’s paid log retention).
If something goes wrong
We will tell the buyer’s named contact within 72 hours of confirming a problem that affects their personal data or confidential engagement files, and say what happened and what we are doing.
Ready answers for vendor questionnaires
| Question | Answer |
|---|---|
| Who is the vendor? | Hortiki Plants LLC, d/b/a Trellis (Hortiki Innovations). |
| What personal data do you hold? | Names and work emails of users; buyer billing details; engagement files and deliverables linked to the client account. |
| Where is data stored? | Cloudflare’s network (D1, R2, KV, Pages/Functions). |
| Is data encrypted? | In transit: TLS. At rest: Cloudflare states D1 uses AES-256; R2 objects are stored in Cloudflare’s infrastructure with provider-managed protections. |
| Which certifications apply? | Cloudflare’s SOC 2 / ISO 27001 claims for covered services. Hortiki itself is not SOC 2 certified. |
| Who has access? | Client users on the engagement, the assigned expert, and Hortiki admin (currently a small team). Hortiki is founder-operated. |
| Sub-processors? | Cloudflare; Stripe (payments when enabled); email provider for magic links; Wise for expert payouts. |
| Is customer data sent to an AI service? | Optional Cloudflare Workers AI may process CoA text for extraction. Heuristic extraction runs in our Workers. Humans review flagged fields. |
| Tracking or advertising cookies? | No ad pixels by default. Session cookie for signed-in use. |
| Penetration tests? | No independent penetration test has been commissioned yet. Say this plainly unless one is done. |
| Insurance? | Confirm current policy; COI available via Buyer center when the PDF is on file. |
| Breach notice? | Within 72 hours of confirming impact to the named contact. |
Confirm before sending to a buyer
- Remote D1 / R2 / KV / AI bindings match what this page describes
- Magic-link email is configured (or bypass is off for production)
- Retention days match the order form / MSA you send
- Insurance and COI wording match the certificate on file
- A lawyer has reviewed Privacy, Terms, and any signed data agreement
← Buyer center · Data storage agreement · Privacy Policy · Sources: Cloudflare D1 data security, Cloudflare compliance