Trust Center

Trust, made visible.

Review the controls Timberline uses to protect customer data, manage access, operate the platform, and support regulated healthcare environments.

Built and operated by Sidechain Security.

88 controls across 12 security domains

Security controls
30Access control · Application security · Vulnerability management · Corporate security
Privacy controls
15Data protection · Privacy & healthcare
Platform controls
24AI & model security · Infrastructure security · Logging & monitoring
Operational controls
19Incident response · Business continuity & recovery · Vendor & third-party risk

Control directory

Controls are grouped by domain. Each entry reflects a practice in place across the Timberline platform and the team that operates it.

Implemented

Access control

8 controls

Access to Timberline is governed by identity, role, and explicit permission. Administrative controls help customers manage who can enter the environment and what they are allowed to access.

  • Single sign-on — Implemented
  • Role-based access — Implemented
  • Tenant administrator controls — Implemented
  • User provisioning and deprovisioning — Implemented
  • Explicit sharing controls — Implemented
  • Access logging — Implemented
  • Privileged access restrictions — Implemented
  • Periodic access review — Implemented

Data protection

8 controls

Customer information is protected throughout its lifecycle, from transmission and storage through retention and deletion.

  • Encryption in transit — Implemented
  • Encryption at rest — Implemented
  • Customer data isolation — Implemented
  • No shared model training — Implemented
  • Defined retention practices — Implemented
  • Secure deletion — Implemented
  • Data classification — Implemented
  • Backup protection — Implemented

Application security

8 controls

Security is part of how Timberline is built and deployed, with controls around code, dependencies, credentials, testing, and production access.

  • Secure software development lifecycle — Implemented
  • Code review — Implemented
  • Dependency scanning — Implemented
  • Vulnerability scanning — Implemented
  • Security testing — Implemented
  • Secrets management — Implemented
  • Environment separation — Implemented
  • Controlled production access — Implemented

Infrastructure security

8 controls

Timberline’s infrastructure is designed to keep customer environments separated and limit access to the systems that operate the platform.

  • Tenant isolation — Implemented
  • Network segmentation — Implemented
  • Firewall controls — Implemented
  • Cloud security monitoring — Implemented
  • Infrastructure access controls — Implemented
  • Backup and recovery — Implemented
  • Environment monitoring — Implemented
  • Configuration management — Implemented

Logging & monitoring

8 controls

Important platform and security activity is recorded and monitored so the team can identify issues, investigate events, and maintain operational visibility.

  • Security event logging — Implemented
  • Audit logging — Implemented
  • Access monitoring — Implemented
  • Infrastructure monitoring — Implemented
  • Service health monitoring — Implemented
  • Alerting and escalation — Implemented
  • Log retention — Implemented
  • Security investigation support — Implemented

Vulnerability management

6 controls

Timberline maintains a defined process for finding, prioritizing, and remediating vulnerabilities across the application and supporting infrastructure.

  • Vulnerability scanning — Implemented
  • Dependency monitoring — Implemented
  • Patch management — Implemented
  • Security issue tracking — Implemented
  • Remediation process — Implemented
  • Responsible disclosure process — Implemented

Incident response

7 controls

Security incidents are handled through a defined response process covering investigation, containment, remediation, communication, and follow-up.

  • Documented incident response process — Implemented
  • Designated response personnel — Implemented
  • Security incident escalation — Implemented
  • Investigation procedures — Implemented
  • Containment and remediation — Implemented
  • Customer notification process — Implemented
  • Post-incident review — Implemented

Business continuity & recovery

7 controls

Timberline maintains operational safeguards designed to support recovery from service interruptions and other disruptive events.

  • Backup procedures — Implemented
  • Backup protection — Implemented
  • Recovery procedures — Implemented
  • Business continuity planning — Implemented
  • Disaster recovery planning — Implemented
  • Service restoration procedures — Implemented
  • Recovery testing — Implemented

Corporate security

9 controls

The people operating Timberline are subject to the same security discipline as the platform itself, with controls around access, devices, training, and personnel lifecycle.

  • Security awareness training — Implemented
  • Employee onboarding controls — Implemented
  • Employee offboarding controls — Implemented
  • Acceptable use requirements — Implemented
  • Confidentiality obligations — Implemented
  • Endpoint security — Implemented
  • Device encryption — Implemented
  • MFA for workforce systems — Implemented
  • Background screening — Implemented

Vendor & third-party risk

6 controls

Vendors that support Timberline are evaluated according to the role they play and the information or systems they may access.

  • Vendor inventory — Implemented
  • Security review for critical vendors — Implemented
  • Subprocessor management — Implemented
  • Contractual security requirements — Implemented
  • Periodic vendor review — Implemented
  • Third-party access restrictions — Implemented

Privacy & healthcare

7 controls

Timberline is designed for organizations handling sensitive healthcare information, with controls addressing how PHI and other customer data may be accessed, used, retained, and protected.

  • Business Associate Agreements available — Implemented
  • PHI handling procedures — Implemented
  • Minimum necessary access principles — Implemented
  • Defined data use — Implemented
  • Retention and deletion requirements — Implemented
  • Subprocessor obligations — Implemented
  • Privacy incident handling — Implemented

Security documentation

Certain security and compliance materials are available to customers and qualified prospects as part of security review.

Request access
  • Security Architecture OverviewOn request
  • Information Security PolicyOn request
  • Incident Response PlanOn request
  • Business Continuity & Disaster RecoveryOn request
  • Vulnerability Management PolicyOn request
  • Access Control PolicyOn request
  • Data Protection & Privacy OverviewOn request
  • Subprocessor ListOn request
  • Business Associate AgreementOn request

Have a security question?

Our team can work directly with your security, privacy, and compliance teams during evaluation.

Ask the team