Skip to content

Security & trust

Your evaluation data is evidence. We treat it that way.

Oloproof holds the inputs, outputs and traces of your AI systems only when you choose to send them. That is sensitive material, so it stays on your machine by default, goes only where you send it, and is never used to train anything.

Certification

Not audited yet

There is no SOC 2 report, audit or penetration test yet, and we will not imply one.

Data residency

Your machine, or Canada

Local runs never leave your machine. The hosted service runs in Canada; its nightly backups are kept for 30 days in Chicago.

Training

Never on your data

Oloproof trains no models at all, on your data or anyone else's.

Access

Roles, scoped keys, an audit log

Owner, Admin, Member and Reviewer roles; API keys scoped and revocable; every sign-off and label in the project's audit log.

How data moves

Ingest. Nothing arrives unless you push it. Your project's egress policy decides what leaves your machine, and the default keeps raw inputs, outputs, traces and dataset rows at home: a push carries the metrics, intervals and decisions, and says which content it withheld.

Grade. Judges run where you run them: on your machine, in your CI, or on a runner in your own infrastructure. A workspace holds your model keys only if you choose managed runs, and then encrypted at rest, decrypted by the worker alone.

Store. Evidence is content-addressed and written once, scoped to its workspace and project. Deleting your account purges every workspace only you belonged to.

Share. Members see what their role allows. A reviewer's browser fetches case content from your own collector, so the workspace never holds it.

Documents

  • Privacy policyRead
  • Terms of serviceRead
  • Who handles data for usView
  • SOC 2 report or penetration testNone yet