Built for the trust your clients place in you.

Tendrill handles client portfolios, custodial data, and conversations on behalf of financial advisors. Here is how we protect that data and who we share it with.

The short version

  • Bank-level encryption in transit and at rest.
  • Zero data retention on AI queries — never used for training.
  • Read-only connections to client portfolio data.
  • All data stored in the United States.

How we protect your data

lock

Bank-level encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Built on bank-grade infrastructure end to end.

trash-2-content

Zero data retention

AI queries run with a zero-retention policy. Nothing you or your clients share is stored on the model side after the response comes back.

shield

No training on your data

Your clients' data is never used to train AI models. It stays in your account and leaves when you say so.

user

Authentication you control

Self-hosted Better Auth with Google sign-in and SMS verification. No third-party identity vendor holds your credentials.

circle-check

Vendor security

Every subprocessor we work with is reviewed for security and compliance practices and held to the standards we set for ourselves.

earth

US data residency

Your data is stored in the United States. Our database, hosting, and core providers all operate in US regions.

Who processes your data

The third-party services we use to run Tendrill. We update this list whenever we add or remove one.

AI & inference

8 vendors
Backup AI provider routed via the Vercel AI Gateway
SOC 2 Type II
United States
Powers the AI assistant (Claude models)
SOC 2 Type II
United States
Google authentication
SOC 2 Type II
United States
OAuth and connector orchestration for third-party integrations
SOC 2 Type II
United States
Web search and sandboxed code execution for AI agent workflows
SOC 2 Type II
United States
Web crawling for firm and prospect research
SOC 2 Type II
United States
People search for meeting prep and prospect research
SOC 2 Type II
United States
Agentic browsing infrastructure
SOC 2 Type II
United States

Financial data

3 vendors
Account connections for prospects and onboarding flows
SOC 2 Type II
United States
Custodial portfolio, holdings, and transactions for clients
SOC 2 Type II
United States
Real-time market data and security pricing
United States

Infrastructure & Ops

4 vendors
Hosting, AI Gateway, sandboxed compute, CDN
SOC 2 Type II
United States (global CDN)
Database and real-time backend
SOC 2 Type II
United States
Error monitoring and crash reports
SOC 2 Type II
United States
Product analytics and usage monitoring
SOC 2 Type II
United States

Communication

3 vendors
SMS verification codes
SOC 2 Type II
United States
Transactional email delivery
SOC 2 Type II
United States
iMessage and RCS delivery
SOC 2 Type II
United States

How to reach us

Questions, feedback, or due diligence requests — David handles them personally.

david@tendrill.ai

Last updated

June 12, 2026

We update this page whenever our practices or subprocessors change.