Security & Privacy
Built by a security professional, for organizations that take data seriously.
Access Proof AI was designed privacy-first from day one. Here is exactly how we protect your data and your code, in plain language you can hand to your IT and security team.
Our seven security and privacy principles
Seven principles govern how Access Proof AI handles your data and your code. Each one is a commitment we design and document against, not a slogan.
-
Principle 1 · Our AI never learns from your data
Zero retention. No training. In writing.
We run on enterprise AI configured for zero data retention and a strict no-training agreement. Your content is used only to generate your fix, then discarded. It is never stored after processing, and it is never used to train any AI model. This is contractual, not a best-effort promise, and it flows through to the agreement we sign with you.
-
Principle 2 · Your code never leaves your control
We suggest. Your team approves.
For remediation, Access Proof AI does not take a copy of your source code to an outside environment. Our AI opens a suggested fix as a pull request inside your own GitHub, GitLab, or Bitbucket, tagged to the exact WCAG rule it solves. Your developer reviews and merges it. For teams with stricter requirements, our engine can run entirely inside your own cloud, so your code never crosses your perimeter at all.
-
Principle 3 · A human is always in the loop
Nothing changes on your site without your approval.
The AI proposes. Your people decide. You control the level of autonomy, starting with suggestions only and increasing it only when you are ready. Access is least-privilege and revocable at any time. We never request more than what is needed to open a pull request.
-
Principle 4 · We send the minimum, and we strip sensitive data
Only what is needed, nothing more.
We audit public web pages, so the content we handle is already public. Even so, we send only the small piece of code needed to diagnose and fix each issue, never your whole site, never backend code, and never personal or form-submitted data. Sensitive fields are stripped before anything reaches the AI.
-
Principle 5 · Canadian data residency
Your data can stay in Canada.
For public-sector and enterprise clients with residency requirements, processing can be kept entirely within Canadian cloud regions.
-
Principle 6 · Built to SOC 2 standards
The controls behind the promise.
Access Proof AI is built around SOC 2 principles covering security, confidentiality, availability, and privacy. That means access controls and audit logging on who can see your results, a documented data flow, vendor risk management on every subprocessor, and change-approval on our own code. Every approval in the platform is logged, which also gives you a clean audit trail.
-
Principle 7 · Responsible AI governance
We hold our AI to the standard we ask you to trust.
Because our whole product asks you to trust AI with your website, we follow responsible-AI governance practices aligned to recognized AI management standards. Governance is not an afterthought here. It is the foundation, and it reflects the professional background of our team.
Trust summary
In one sentence.
The AI never trains on your data, your code never leaves your control, every change is reviewed by your team, and everything is documented against the exact WCAG rule it solves.