Data & Security
How TrustHuman handles your endpoint credentials and assessment data when you run an assessment.
What we do
✓
Credentials handled server-side only
Your endpoint URL and auth token are sent directly to TrustHuman's serverless function. They are used only to run the assessment and are never stored, logged, or exposed to the browser beyond your session.
✓
Assessment scores stored securely for quality assurance
When you run an assessment, TrustHuman stores your endpoint's domain (hostname only — not the full URL, path, or credentials), your overall score and pillar results, and any optional label you provide. This data is held securely and used internally to monitor assessment quality. Your auth tokens and full endpoint URL are never stored.
✓
Account required — email collected under contract performance
To run an assessment you must have a TrustHuman account. Your email address is collected when you register and is used solely to authenticate you and associate your assessments with your account. This is the only personal data we collect from you. Lawful basis: contract performance. No cookies or third-party tracking.
✓
AI assessment engine — zero data retention
TrustHuman's assessment engine operates under zero data retention terms. Content processed during assessment is not stored by our AI provider and is not used to train any AI models.
What we're honest about
—
TrustHuman is operated by TrustHuman Ltd. Our privacy policy and data processing information are set out on this page.
—
TrustHuman has not yet been independently security audited or penetration tested. If your organisation requires a formal security questionnaire response before proceeding, please get in touch.
—
The probe inputs TrustHuman sends to your endpoint are visible in your endpoint's own logs. If your AI tool logs all requests, the test inputs will appear there.
Questions about data handling? Contact us before running an assessment.