How we protect your images, your keys, and your customers. SOC 2 Type II audited annually. GDPR compliant. Encryption everywhere. Configurable retention up to and including zero.
We treat every image as sensitive. The default posture is to retain the minimum required and to delete on a schedule that you can shorten further.
| Item | Free / Pro | Enterprise |
|---|---|---|
| Image bytes | Discarded after detection | Configurable, zero-retention available |
| Detection results | 30 days | Configurable, 0 to 7 years |
| API request logs | 30 days | Configurable + SIEM export |
| Account audit logs | 90 days | 7 years (compliance-grade) |
| Heatmap PNGs | 7 days | Configurable |
Enterprise customers can also choose EU regional data residency (Frankfurt) or US-only processing.
Owner, Admin, Developer, and Viewer roles in the dashboard. Granular API-key scoping on Pro and above.
Google Workspace, Okta, Azure AD, and generic SAML 2.0 on Enterprise. SCIM provisioning available.
Restrict API keys to specific IP CIDR ranges. Available on Pro and Enterprise.
TOTP required for all admin actions. Enforceable org-wide on Enterprise.
Every dashboard action and API request is logged with actor, IP, and request_id. Exportable as CSV or pushed to your SIEM.
Programmatic key rotation with overlap window so deploys never break. Hourly rotation supported.
We run on AWS in multiple regions with isolated VPCs, dedicated GPU clusters on Enterprise, and full network segmentation between customer environments.
Audited annually by an AICPA-licensed firm. Report available under NDA.
EU regional endpoints, DPA template, DSAR workflow, sub-processor list.
California consumer rights honored. Opt-out and deletion workflows in dashboard.
Business Associate Agreement available on Enterprise for healthcare workloads.
Roadmap target Q4 2026. Controls already mapped.
Not applicable — we never see card data. Stripe handles billing.
We disclose every third-party service that processes customer data. Notice of changes is given 30 days in advance; Enterprise customers may object.
| Vendor | Purpose | Region |
|---|---|---|
| AWS | Infrastructure, compute, storage | US, EU, APAC |
| Cloudflare | CDN, DDoS protection, DNS | Global |
| Stripe | Subscription billing, payment processing | US |
| Datadog | Observability, metrics, alerting | US |
| Sentry | Error tracking | US |
| PostHog | Product analytics (self-hosted) | US, EU |
Our on-call rotation is 24/7. P0 incidents trigger Slack + PagerDuty + SMS alerts within 60 seconds and a public status page update within 15 minutes.
We welcome reports from security researchers. Email security@aiimagedetectorapi.com with details. We commit to:
PGP key fingerprint available at /.well-known/security.txt.
SOC 2 reports, pen test summaries, sub-processor lists, BAA, and DPA templates are available on request.