Trust Centre

How Proofroom AI handles evidence, data and access — so buyers can diligence without a founder face on the homepage.

Five-line integration

curl -X POST https://proofroom.ai/api/events \
  -H "Authorization: Bearer prf_live_…" \
  -H "Content-Type: application/json" \
  -d '{"use_case_slug":"your-room","event_type":"task_completed","event_summary":"…"}'

Full docs: Getting started · OpenAPI

Architecture & data flows

Agents record evidence events over HTTPS (REST, webhook or MCP). Events are append-only hash-chained per room. Public rooms expose structural status; free-text detail stays sealed unless explicitly published.

Encryption in transit (TLS). At rest via the managed database provider. Operator access is role-scoped (owner / member / reviewer).

Retention & subprocessors

Evidence rows are retained for integrity; commercial plan limits affect detail visibility, not silent deletion of hashes. See plans and retention.

Typical subprocessors: hosting (Vercel), database (Supabase), email (Resend), LLM providers for internal ops agents only. DPA / region detail: contact support@proofroom.ai.

Assurance roadmap

Security contact: /security · security.txt