PinkSpider is designed to support accountable marketing decisions, not replace them. We are clear about what the platform does, where human judgment belongs, and how we approach data protection.
Medium and lower-risk flags can move automatically. Higher-risk flags route to a named reviewer, and their decision, not the AI's flag, is the record.
Every flag links to the exact caption, transcript, or frame that triggered it, so reviewers see why it was raised, not just that it was.
AI drafts suggestions and surfaces risk. Routine, lower-risk items can proceed automatically; higher-risk output is gated by a human review step before it acts.
No shared logins. Each role sees and acts on only what its job requires, and roles and permissions are configurable and auditable.
Every brand's data, content, and rules are scoped to its own workspace. Access to another brand's data requires an explicit, permissioned role.
Sensitive fields like personal information and credentials are encrypted at rest. We're upfront about what's retained and why.
Read the privacy policyAccess changes, sign-ins, and review decisions are logged and available to your admins. Coverage is strongest for security and review actions.
Traffic between your browser, our integrations, and PinkSpider is encrypted in transit, so data isn't exposed as it moves.
If something goes wrong, we investigate, contain the issue, and notify affected teams without delay.
PinkSpider is not a law firm. Nothing it produces is legal counsel.
A flag means something is worth a closer look, not that a violation occurred.
Laws, platforms, and brand standards change. Final judgment stays with your reviewers.
PinkSpider surfaces what a reviewer should look at. The call, and the responsibility, is theirs.
We don't publish our detection rules, model thresholds, or security architecture. That keeps results resistant to gaming for everyone using the platform. If your team has security, privacy, or compliance questions, reach out and we'll answer them directly.
Beyond the principles above, here is a high-level look at the access and account controls already in the product today.
Password requirements, two-factor authentication, and email verification codes protect every account, with alerts for sign-ins people don't recognize.
Custom roles are gated to specific permissions, including a dedicated permission for regulatory reviewers so sensitive work stays with the right people.
Users can view active sessions, sign out one or all of them, and admins can set session timeout policies for the workspace.
Media and documents are served through secure, signed access rather than open links, reachable only by the people and systems meant to see them.
Our scoped REST API and MCP access use tokens with expiration and revocation, so a team can grant integration access and cut it off just as easily.