Ontario’s next AODA accessibility compliance report is due December 31, 2026. See where your website stands. Run a free scan

Security & Privacy

Built by a security professional, for organizations that take data seriously.

Access Proof AI was designed privacy-first from day one. Here is exactly how we protect your data and your code, in plain language you can hand to your IT and security team.

A geometric illustration of a locked padlock inside a protective cloud, ringed by keys and a maple leaf motif, representing encrypted processing with Canadian data residency.

Our seven security and privacy principles

Seven principles govern how Access Proof AI handles your data and your code. Each one is a commitment we design and document against, not a slogan.

  1. Principle 1 · Our AI never learns from your data

    Zero retention. No training. In writing.

    We run on enterprise AI configured for zero data retention and a strict no-training agreement. Your content is used only to generate your fix, then discarded. It is never stored after processing, and it is never used to train any AI model. This is contractual, not a best-effort promise, and it flows through to the agreement we sign with you.

  2. Principle 2 · Your code never leaves your control

    We suggest. Your team approves.

    For remediation, Access Proof AI does not take a copy of your source code to an outside environment. Our AI opens a suggested fix as a pull request inside your own GitHub, GitLab, or Bitbucket, tagged to the exact WCAG rule it solves. Your developer reviews and merges it. For teams with stricter requirements, our engine can run entirely inside your own cloud, so your code never crosses your perimeter at all.

  3. Principle 3 · A human is always in the loop

    Nothing changes on your site without your approval.

    The AI proposes. Your people decide. You control the level of autonomy, starting with suggestions only and increasing it only when you are ready. Access is least-privilege and revocable at any time. We never request more than what is needed to open a pull request.

  4. Principle 4 · We send the minimum, and we strip sensitive data

    Only what is needed, nothing more.

    We audit public web pages, so the content we handle is already public. Even so, we send only the small piece of code needed to diagnose and fix each issue, never your whole site, never backend code, and never personal or form-submitted data. Sensitive fields are stripped before anything reaches the AI.

  5. Principle 5 · Canadian data residency

    Your data can stay in Canada.

    For public-sector and enterprise clients with residency requirements, processing can be kept entirely within Canadian cloud regions.

  6. Principle 6 · Built to SOC 2 standards

    The controls behind the promise.

    Access Proof AI is built around SOC 2 principles covering security, confidentiality, availability, and privacy. That means access controls and audit logging on who can see your results, a documented data flow, vendor risk management on every subprocessor, and change-approval on our own code. Every approval in the platform is logged, which also gives you a clean audit trail.

  7. Principle 7 · Responsible AI governance

    We hold our AI to the standard we ask you to trust.

    Because our whole product asks you to trust AI with your website, we follow responsible-AI governance practices aligned to recognized AI management standards. Governance is not an afterthought here. It is the foundation, and it reflects the professional background of our team.

Trust summary

In one sentence.

The AI never trains on your data, your code never leaves your control, every change is reviewed by your team, and everything is documented against the exact WCAG rule it solves.

Talk to us about your security requirements

Share with