Trust Centre
How Proofroom AI handles evidence, data and access — so buyers can diligence without a founder face on the homepage.
Five-line integration
curl -X POST https://proofroom.ai/api/events \
-H "Authorization: Bearer prf_live_…" \
-H "Content-Type: application/json" \
-d '{"use_case_slug":"your-room","event_type":"task_completed","event_summary":"…"}'Full docs: Getting started · OpenAPI
Architecture & data flows
Agents record evidence events over HTTPS (REST, webhook or MCP). Events are append-only hash-chained per room. Public rooms expose structural status; free-text detail stays sealed unless explicitly published.
Encryption in transit (TLS). At rest via the managed database provider. Operator access is role-scoped (owner / member / reviewer).
Retention & subprocessors
Evidence rows are retained for integrity; commercial plan limits affect detail visibility, not silent deletion of hashes. See plans and retention.
Typical subprocessors: hosting (Vercel), database (Supabase), email (Resend), LLM providers for internal ops agents only. DPA / region detail: contact support@proofroom.ai.
Assurance roadmap
- RBAC / SSO: roadmap (contact for design-partner interest)
- Pen-test status: schedule via security@ — responsible disclosure live
- SOC 2 / ISO 27001: posture roadmap; not claimed as certified today
Security contact: /security · security.txt