← TrustLens AI

Security & Data Protection

Straight answers to the questions that matter. We're a verification company — we'd rather tell you exactly where we are today than paste impressive-sounding boilerplate.

Last updated: July 28, 2026

How is my data protected?

All traffic between your browser and TrustLens is encrypted in transit with TLS (HTTPS). Data at rest is stored in Supabase (PostgreSQL hosted on AWS), which encrypts stored data at rest. The application is hosted on Vercel.

Access to the production database is restricted to server-side application code using secret credentials — there is no public read access to stored documents.

Do you train AI models on my documents?

No. Analysis is performed via Anthropic's Claude API. Anthropic does not train its models on API inputs or outputs by default, and we do not train any models of our own on your content.

Who processes my document when I analyze it?

Two parties: our servers (extraction, scoring, storage) and Anthropic's Claude API (the AI analysis itself). For AI answer verification, factual claims are also sent to a web search API (Tavily) to find supporting evidence — the search queries contain claim text, not your full input.

How long are files stored?

We don't store your uploaded file itself — we extract the text and discard the file. The extracted text and the analysis report are stored so your saved report and share link keep working. They are currently retained until you ask us to delete them.

Prefer nothing stored at all? Turn on 🔒 Privacy Mode before analyzing: the document is processed in memory only, no report is stored, no share link is created, and everything is gone when you leave the page.

Can I delete my reports?

Yes — email wnguyen@myinfinivue.com with the report link and we'll delete the report and the stored document text. Self-service deletion is on the roadmap.

Who can see my reports?

Reports live at unlisted URLs — they are not listed publicly, not indexed on the site, and not shown to other users. Anyone who has the exact link can view the report, so treat a report link like the document itself: only share it with people you'd show the document to.

Are you SOC 2 / HIPAA / ISO 27001 certified?

Not yet — we're an early-stage product and won't claim certifications we don't hold. Don't upload documents containing protected health information or data you're not authorized to share. If your organization needs compliance guarantees, email us — enterprise controls are planned, and we'd rather build them with a real customer than guess.

What's on the security roadmap?

Planned as we grow into enterprise customers: SOC 2 certification, single sign-on (SSO), audit logs, and an enterprise workspace with team controls. None of these exist today — when they ship, this page will say so. If one of them is a blocker for your organization, email us; we prioritize with real customers.

What should I NOT upload?

Documents you aren't authorized to share, protected health information, and anything containing credentials or payment card numbers. Redact what isn't needed for the analysis — the tool works fine with names and account numbers blacked out.

Questions we didn't answer? Email wnguyen@myinfinivue.com. See also the Trust Center, privacy policy, user agreement, and documentation.