sealverity.ai
Trust Center

Security & responsible AI

How we protect evidence, who processes it, and where we are on the path to independent certification.

Security overview

Every user must use an authenticator app (TOTP). Organisations can add SAML single sign-on, SCIM provisioning, idle timeouts and an IP allow-list.

Access is role-based (Viewer, Auditor, Analyst, Supervisor, Org Admin) and enforced by database access rules on every request, not only in the interface. Each organisation's data is isolated from every other organisation.

Every important action is written to an append-only, hash-chained audit log that can be exported or streamed to a SIEM.

Encryption

All traffic uses TLS 1.2 or higher. Databases and file storage are encrypted at rest (AES-256). Provider keys and signing keys are kept as server-side secrets and never reach the browser.

Forensic reports and deletion certificates are signed with Ed25519; sealed content uses C2PA Content Credentials.

Data handling

Each original file is fingerprinted (SHA-256) on intake and kept in private storage. Files are sent only to the detection providers your organisation has switched on.

Organisations choose a data region and retention period per media type. Originals past retention are deleted nightly, except evidence in open cases or under legal hold, and a signed deletion certificate is issued.

Face match is off by default, searches only collections the organisation owns, and needs a recorded reason for every search.

Sub-processors

ProviderPurposeProcessing region
AI or NotImage, video and audio deepfake detectionUnited States
HiveImage, video and audio deepfake detectionUnited States
Reality DefenderImage, video and audio deepfake detectionUnited States
SightengineImage and video AI-generation detectionEuropean Union (France)
Resemble AISynthetic voice detectionUnited States
AssemblyAITranscription and audio intelligenceUnited States
AWS RekognitionFace detection and organisation-scoped face match (opt-in)Region configured for the account
GPTZeroAI-written text detection (when enabled)United States
Lovable AI (Google Gemini models)Visual review, summaries, text checks, Ask assistantUnited States
Lovable CloudHosting, database, authentication, file storagePlatform region

Regions are as published by each provider. Each organisation only uses the providers it has enabled.

Compliance roadmap

  • SOC 2 Type II — controls being put in place; audit planned.
  • ISO/IEC 27001 — information security management system in preparation.
  • EU AI Act, Article 50 — AI-generated content labelling supported through C2PA sealing and reading.

Responsible AI

Detection scores are probabilities, not proof. sealverity.ai combines several independent detectors, shows when they disagree, and never makes a final decision: a trained analyst does, with a recorded reason.

Accuracy is measured on labelled test sets and published as aggregates. Risk scores support analyst judgement and are not determinations about any person.

Security contact

Report a vulnerability or security concern to security@lavisho.com. We acknowledge reports within two business days.