PinkSpider Trust Center

    Trust is part of the product.

    PinkSpider is designed to support accountable marketing decisions, not replace them. We are clear about what the platform does, where human judgment belongs, and how we approach data protection.

    Human review on higher-risk flags
    Evidence-linked findings
    Role-scoped access
    Full audit trail
    Brand-level data isolation

    Human accountability

    Medium and lower-risk flags can move automatically. Higher-risk flags route to a named reviewer, and their decision, not the AI's flag, is the record.

    Evidence-backed review

    Every flag links to the exact caption, transcript, or frame that triggered it, so reviewers see why it was raised, not just that it was.

    AI-assisted, human-gated

    AI drafts suggestions and surfaces risk. Routine, lower-risk items can proceed automatically; higher-risk output is gated by a human review step before it acts.

    Scoped access & permissions

    No shared logins. Each role sees and acts on only what its job requires, and roles and permissions are configurable and auditable.

    Brand & tenant separation

    Every brand's data, content, and rules are scoped to its own workspace. Access to another brand's data requires an explicit, permissioned role.

    Data handling

    Sensitive fields like personal information and credentials are encrypted at rest. We're upfront about what's retained and why.

    Read the privacy policy

    Audit history & traceability

    Access changes, sign-ins, and review decisions are logged and available to your admins. Coverage is strongest for security and review actions.

    Encrypted in transit

    Traffic between your browser, our integrations, and PinkSpider is encrypted in transit, so data isn't exposed as it moves.

    Incident response

    If something goes wrong, we investigate, contain the issue, and notify affected teams without delay.

    What PinkSpider is not

    Being clear about the boundaries.

    Not legal advice

    PinkSpider is not a law firm. Nothing it produces is legal counsel.

    A signal, not a verdict

    A flag means something is worth a closer look, not that a violation occurred.

    No compliance guarantees

    Laws, platforms, and brand standards change. Final judgment stays with your reviewers.

    People, not a replacement

    PinkSpider surfaces what a reviewer should look at. The call, and the responsibility, is theirs.

    We don't publish our detection rules, model thresholds, or security architecture. That keeps results resistant to gaming for everyone using the platform. If your team has security, privacy, or compliance questions, reach out and we'll answer them directly.

    Product controls

    Real controls, described plainly.

    Beyond the principles above, here is a high-level look at the access and account controls already in the product today.

    Access & identity

    Password requirements, two-factor authentication, and email verification codes protect every account, with alerts for sign-ins people don't recognize.

    Roles & permissions

    Custom roles are gated to specific permissions, including a dedicated permission for regulatory reviewers so sensitive work stays with the right people.

    Session controls

    Users can view active sessions, sign out one or all of them, and admins can set session timeout policies for the workspace.

    Private media & documents

    Media and documents are served through secure, signed access rather than open links, reachable only by the people and systems meant to see them.

    API & MCP access

    Our scoped REST API and MCP access use tokens with expiration and revocation, so a team can grant integration access and cut it off just as easily.

    Have a security or compliance question for our team?

    We'd rather answer directly than leave it to marketing copy.