Every complaint on the record. Every risk on the register.
Trumis records each complaint exactly as the person confirmed it — verbatim narrative, ticked claims, evidence annexed, reference-stamped, lodged under your own complaint-handling policy — and tiers every open matter on an executive register by modelled exposure and response clock. Nothing is summarised or softened between your customer and your accountable executive. People still just talk — any language, voice or text; the structure is Trumis's job.
What your team receives
Intake on your page
People talk, in their language
English, 中文, Tiếng Việt, العربية, Ελληνικά — voice or text, no form fields, at most one gentle question per turn.
Evidence is read on their device
Screenshots of chats and letters are OCR’d in the browser; images never leave the person’s device. They approve the reconstructed record before it is used.
Claims are ticked, not assumed
The AI never decides merit — a deterministic rules engine does — and nothing is written unless the person explicitly confirmed it. Your team can rely on what it reads.
You receive it, not us
The person sends from their own email (embed), or your systems capture the structured object (API). Your inbox is the record of receipt, and the register holds category codes only — never names, contact details or anyone's words.
People talk, in their language
English, 中文, Tiếng Việt, العربية, Ελληνικά — voice or text, no form fields, at most one gentle question per turn.
Evidence is read on their device
Screenshots are OCR’d in the browser; raw images stay on-device. The approved extracted text is retained with the intake.
Claims are ticked, not assumed
The AI never decides merit — a deterministic rules engine does — and nothing is written unless the person explicitly confirmed it. Your team can rely on what it reads.
Controlled complete record
Trumis retains an encrypted complete intake for up to 24 months. Client access stays tenant-isolated; named platform-administrator reads are audited.
Record-keeping, RG 271 and ombudsman schemes
RG 271 expects financial firms to address the issues a complaint raises within the response window — 30 calendar days for most. Structured intake means the clock starts on a complaint your team can actually action; reconstruction time is the single biggest driver of blown IDR timeframes.
The email in your inbox or API object remains your operational record. Trumis also retains the encrypted conversation, facts, extracted evidence text, generated document and routing for controlled support and assurance access.
Licensed intake includes a risk-tiered view of what arrived: critical / elevated / watch, urgency, evidence strength, amount bands — each row matched to the complaint in your inbox by the Reference: TRM-… line printed on it. Category codes only; it structurally cannot hold anyone’s words.
Documents carry the complainant’s identity as they typed it, the location, date and people involved, and a records-preservation request — the details AFCA, the TIO and state ombudsmen ask for, captured before escalation ever happens.
Consumer-side documents name the correct external scheme with response clocks. Complaints that reach an ombudsman as “the organisation never understood my complaint” are the expensive ones; intake that listens is how they stop.
Every generated complaint maps to named arguments in a maintained legal knowledge base (grounds.passed_arguments in the API) — you can see why the engine considered grounds to exist.
Posture, stated plainly
No accounts, and no conversation state held between turns. What is stored, in Australia: content-free category codes for the register and statistics, and an encrypted, access-audited intake service record. The full model is published at trumis.com.au/security.
Hosted on Vercel, served from Australia, API compute pinned to Sydney. The one overseas flow — AI provider processing of conversation text, typically US — is disclosed in the Privacy Policy. APP 8 relevant.
A sandboxed iframe: no scripts in your page context, no access to your DOM, and verified partner branding resolves server-side so it cannot be impersonated.
We are open about not yet holding SOC 2, ISO 27001 or IRAP. The architecture deliberately minimises what such an audit would need to protect.
We answer security questionnaires and support your pen-testing of a pilot.
Vulnerability reports via security.txt at trumis.com.au/.well-known/security.txt.
Complete server-processed intakes are encrypted in a controlled archive for up to 24 months, with tenant isolation and audited named-administrator access. The full model is published at trumis.com.au/security.
Hosted on Vercel, served from Australia, API compute pinned to Sydney. The one overseas flow — AI provider processing of conversation text, typically US — is disclosed in the Privacy Policy. APP 8 relevant.
A sandboxed iframe: no scripts in your page context, no access to your DOM, and verified partner branding resolves server-side so it cannot be impersonated.
We are open about not yet holding SOC 2, ISO 27001 or IRAP. The architecture deliberately minimises what such an audit would need to protect.
We answer security questionnaires and support your pen-testing of a pilot.
Vulnerability reports via security.txt at trumis.com.au/.well-known/security.txt.
From pilot to licence
Pilot, self-serve
Paste the one-line embed on a test or live complaints page. Watermarked, complaints pre-addressed to your inbox. No contract, no call required.
Evaluate
Your team reads real intake output and forms its own view. We are available at info@trumis.com.au throughout.
Licence
A written agreement covers verified branding, watermark removal, registered page origins, API keys with raised limits, support commitments and data-processing terms.
Starter licence
Smaller organisation? The self-serve Starter covers the same verified, unbranded embed at a public price — pay by card, live within one business day of verification.