Sign up →
Help Center › Guide
Guide

Security, data, and backups

Learn how Trellis protects workspace data and how administrators can back up and restore it.

Trellis separates data by workspace and enforces permissions on the server. This guide covers what that means in practice and what administrators should set up.

Access is enforced on the server

Permission checks run again on the server when an action is submitted, not only in the interface. Hiding a control is a convenience, and the server check is the actual protection. A blocked action returns a clear error instead of failing silently, which also makes misconfiguration easy to spot.

Workspaces are isolated from each other

Data belongs to a workspace and is scoped to it on every query. A person or guest working in one workspace cannot reach records in another, even by guessing an identifier, because the workspace is part of the lookup rather than a filter applied afterwards.

Use the audit log to answer who did what

The audit log records permission-sensitive actions with the actor and a timestamp. Owners and Admins can read it. Free and Studio show recent activity, while Agency and Scale retain extended history, which matters if you ever need to reconstruct a sequence of events months later.

Set up backups and know how restore works

Automatic scheduled backups and workspace restore are available on Agency and above. Restore is an administrative action, so confirm who holds that authority before you need it. On any paid plan you can also export a project, which is a useful way to keep a portable copy of a specific engagement.

Keep access current

The most common real-world exposure is not a technical failure but an account that should have been closed. Disable people who leave rather than leaving them active, review who holds Admin periodically, and remove guest shares when an engagement ends.

Worth remembering

  • Prefer disabling an account over deleting it, so the history stays attributable.
  • Project export gives you a portable copy without needing a full restore.
  • Backups and restore are Agency features. Project export is available from Studio.
Questions

Common questions

Restore is limited to Owners and Admins, and the feature is available on Agency and above.

No. Guests are scoped to the specific projects shared with them, and workspace isolation is enforced on the server.

Ready to apply this?

Bring a real project into Trellis with guided onboarding, or ask us anything about your setup.