Security at Safe Trust AI
We handle media that organizations cannot afford to mishandle. This page describes how the platform treats data, access, and evidence today — in plain terms, without overstating what is in place.
Security overview
Safe Trust AI examines media to produce an authenticity verdict and an evidence record. Our approach to security follows from that purpose: process only what is needed, keep a clear record of what happened, and give each customer control over where their media goes and how long it stays.
Security and compliance documentation can be reviewed during vendor assessment. We would rather walk a prospective customer through the actual state of our controls than point to a badge.
Data handling
Media submitted for examination is processed to generate a verdict and the associated evidence record. We operate on a data-minimization basis: we work with the file that is needed for the analysis, and we do not repurpose customer media for unrelated uses.
- Examination can run in a region the customer selects, so media does not have to leave a chosen jurisdiction.
- Dedicated and on-premise deployments are available for teams that cannot send media outside their own environment.
- Media in transit and at rest is protected using standard encryption practices.
Access controls
Access to customer data is limited to what is required to operate the service and support the customer. Console access for a customer organization is provisioned during onboarding and managed per organization.
- Role-based access for customer console users.
- Internal access to customer media is restricted and limited to operational need.
- Authentication and access details for the customer portal are set up during onboarding.
Evidence trail
Every verdict is accompanied by an evidence record: the signals that were evaluated, how they contributed, provenance information, and the reviewer trail where applicable. The record is designed to be exportable and reviewable, so a decision can be explained to an auditor, regulator, or counsel rather than taken on trust.
Retention and deletion
Retention is controlled by the customer’s policy. Media and records are kept for the period the customer configures, and deletion can be performed in line with that policy and applicable obligations. Where a customer requires it, media can be processed and then removed rather than retained.
Compliance posture
We are transparent about what is in place now versus what is on the roadmap. Where formal certifications or attestations apply, we will share their current status directly during evaluation rather than imply a status we have not reached.
Security and compliance documentation, including details relevant to a vendor security review, can be provided under NDA as part of a vendor assessment.
Responsible use
Authenticity examination is a tool for informed human decisions, not an automatic judgment of a person. We expect the platform to be used with appropriate review, calibrated thresholds, and respect for the people whose media is examined. See our responsible use page for how we think about this.
Request security documentation
Running a vendor security review? We can share our current security and compliance documentation under NDA, and walk your team through how data, access, and retention work for your deployment.
Request security documentation