Security & trust

Trust is the product.

ToneAudit exists to produce defensible evidence. That standard applies to how we handle your data, too.

How every check becomes evidence

Nothing is taken on trust. Each check is preserved so it can be proven later — the same way an auditor would want it.

01

Access

Official API or public source, accessed with rate limits respected.

02

Snapshot

The exact page or record captured as it was at that moment.

03

Hash

A SHA-256 content hash proves the snapshot hasn't changed.

04

Timestamp

The access time is recorded for the audit trail.

05

Preserve

Stored as evidence, scoped to your workspace.

Security practices

Data protection
  • Encrypted in transit (TLS) and at rest
  • Access scoped per workspace, least-privilege
  • No cross-customer data sharing
  • Supplier data is never used to train shared models
Evidence & audit
  • Source snapshots, hashes and timestamps preserved
  • Every source access and reviewer decision logged
  • Zero-hallucination audit — nothing inferred
  • Configurable retention per workspace
Responsible access
  • Official APIs used where available
  • robots.txt and rate limits respected
  • Only sources relevant to a check are accessed
Privacy
  • Focus on publicly available business data
  • Personal data minimised and purpose-bound
  • GDPR-aware processing and data-subject rights

Have a security or data-processing question? Contact us.