Enterprise-gradesecurity.

Learn how Trails helps keep your guides and training videos protected and secure.

Protection at every step

  • SOC 2 Type II compliant
  • HIPAA support with BAAs available
  • On-device redaction before upload
  • Independent penetration testing
  • Encryption in transit and at rest
  • Customer data is never used to train AI models
AICPA SOC for Service Organizations badge

SOC 2 Type II compliance, independently audited

Trails has completed a SOC 2 Type II audit, giving your team independent evidence that our security controls operated effectively over time.

Request the report and review our supporting policies, subprocessors, and current compliance details in the Trails Trust Center.

Review SOC 2 details

Document sensitive work without exposing sensitive information

Real workflows often touch customer records, financial systems, and internal data. Trails helps you remove sensitive information before it reaches our servers or appears in a shared guide.

Blur sensitive information before upload

On-device Secure Blurring runs on your device, before any screenshots leave your machine. Review the capture, then blur names, account details, or anything else that should stay private before uploading it to Trails.

Redact screenshots in the editor

Spot something you missed? Blur it in the screenshot editor before sharing the guide. Redaction is built into the same editing flow you use to clean up each step.

Decide who can see each guide

Keep a guide private, share it with your team, or publish it for a wider audience. You can control viewing and editing access and protect public links with a password.

Blur sensitive info

Email addresses
Names
Numbers
CustomerEmailAccount
Lena Ortiz[email protected]AC-1048
Noah Kim[email protected]AC-2091
Maya Chen[email protected]AC-3157

Give people access without giving up control

Documentation is easier to manage when the access settings are centrally managed. Trails gives your team one place to create, share, and manage each guide.

Enterprise SSO

Connect Trails to your identity provider and use the sign-in policies your organization already manages. Enterprise SSO supports Microsoft Entra ID and other SAML-based providers.

Roles and permissions

Assign viewer, editor, and admin roles across your organization. Then use guide-level permissions to control who can view or change specific content.

Flexible sharing

Choose Private, Team, or Public access for each guide. When sharing externally, you can add password protection without inviting every viewer into your Trails workspace.

Your data stays protected after upload

Encryption in transit

Trails uses TLS 1.2 or higher to protect data as it moves between your device, the Trails application, and our supporting services.

Encryption at rest

Sensitive customer data is encrypted at rest using AES-256 or an equivalent standard. Uploaded screenshots and media are stored in access-controlled cloud storage with no public directory listing.

Restricted production access

Production access is limited to the people who need it for their work. Administrative access requires multi-factor authentication, and permissions are reviewed regularly.

Data minimization and deletion

We collect and retain the information needed to provide Trails. We honor customer deletion requests. Retention follows account settings, product deletion behavior, and any contractual terms agreed with your organization.

Built to support HIPAA-regulated work

Trails helps consultants, service providers, health-tech companies, and other organizations protect sensitive healthcare data with on-device redaction, role-based access, encryption in transit and at rest, and secure data handling. Business Associate Agreements are available for eligible customers.

Talk to us about HIPAA
Trails with the OpenAI and Google Gemini logos

How Trails uses AI

Trails uses AI for specific tasks, including writing step instructions, transcribing recordings, translating guides, and generating narration. These features run only when you or an enabled product workflow triggers them.

Trails does not train or fine-tune AI models on customer data.

We use providers including OpenAI, Google Gemini, and ElevenLabs for specific AI features. Customer content goes only to the provider needed to complete the requested task. You can review and edit generated text, transcripts, translations, and narration before publishing or exporting them.

See our current provider list and data-handling information in the Trails Trust Center.

Security is part of how we build and run Trails

Reviewed changes

Production code changes must be reviewed before being released. Changes involving authentication, payments, permissions, or customer data receive extra scrutiny.

Vulnerability management

We scan dependencies for known vulnerabilities, review third-party services before adding them, and prioritize security patches by severity.

Monitoring and incident response

Trails monitors authentication activity, service health, errors, and unusual behavior. We follow documented procedures to contain, investigate, communicate, and learn from security incidents.

Independent testing

Trails has completed an independent penetration test and repeats testing annually. We review findings and address them based on severity.

Backups and recovery

Our production database is backed up automatically every day. Documented business continuity and disaster recovery procedures help us restore service after an outage or security event.

Team and device security

Team members complete security awareness training. Work devices use disk encryption and screen locks. Access is removed when someone leaves the company.

Security FAQs

No. Trails does not train or fine-tune AI models on customer data. AI providers receive content only when needed to deliver a feature you use, such as transcription, translation, step generation, or narration.
Yes. Smart Blurring processes redaction on your device before upload. You can also blur sensitive areas in the screenshot editor before sharing a guide.
Trails supports Private, Team, and Public guide access, separate view and edit permissions, organization roles, password-protected public links, search-indexing controls, and enterprise SSO.
Trails uses TLS 1.2 or higher for data in transit and AES-256 or equivalent encryption for sensitive data at rest.
Trails uses DigitalOcean and AWS for cloud infrastructure, storage, and media workflows. Current infrastructure and subprocessor information is available in the Trust Center.
Yes. Trails is SOC 2 Type II compliant. Request our current report and supporting documentation through the Trust Center.
Yes. Trails supports HIPAA-regulated healthcare workflows and can enter into a Business Associate Agreement with eligible customers. Contact our team to confirm that your intended use is within scope.
Yes. Start with the Trust Center. Then contact us with your security questionnaire or any requirements specific to your organization.

Give your security team the proof

Review our SOC 2 Type II report, HIPAA support, controls, policies, subprocessors, and current compliance details in the Trails Trust Center. If you need a Business Associate Agreement or have other specific requirements, send them our way. We will give you a direct answer.