Trust

Trust, security and provenance

Last updated: 11 October 2026

Data for AI is only as good as its paper trail. This page says what we do, what we don't do, and what isn't in place yet. If anything changes, we update the page and the date.

01Where our data comes from

  • Environments: original interfaces and synthetic seed data. No real guest, employee or company records. We don't copy third-party websites or use trademarks.
  • Expert tasks: written from scratch by contracted professionals who assign their IP to us. No client files, no scraped content, no reuse of employer documents.
  • Real-world environments: sites or workspaces set up for the purpose, or venues under a signed site agreement. Built to order; none exists yet.
  • Capture (video, sensors, screen): recorded only with adult participants who have given separate, informed, withdrawable consent, in venues that have signed a site agreement.
  • We don't broker data. We don't resell operators' business records or customer data. If a business contributes knowledge of its workflows, it does so on its own contract and its own terms.

02Provenance record

Every delivered item carries a record: pseudonymous author or participant ID, consent-form version (video), venue code (video), creation date, reviewer IDs and version history. Buyers receive the record with the data, which supports their EU AI Act documentation of training content.

  • Separate from employment: taking part, or not, has no effect on anyone's job, pay or shifts. Participants are paid directly for their time.
  • Purpose-specific: consent covers the stated purpose (training and evaluating AI systems, by named categories of recipient) and nothing else.
  • Withdrawable: a participant can withdraw at any time. We stop using their footage for new deliveries and tell buyers, as set out in the consent notice.
  • Back-of-house only. No guest audio. People who haven't consented, and screens with personal data, are blurred.
  • Adults only. No minors on camera.
  • Before the first recording: Spanish counsel/DPO review of the consent pack and a completed Data Protection Impact Assessment (DPIA). Status today: templates drafted, legal review pending; no recording has taken place.

04GDPR

  • Personal data (video, contributor records) is to be processed and stored in the EU.
  • Competent authority: Agencia Española de Protección de Datos (AEPD).
  • A Data Processing Agreement is available on request, with subprocessor list, breach notification within 72 hours, deletion or return at end of contract and audit cooperation (draft, pending legal review).
  • Transfers outside the EEA only under the EU-US Data Privacy Framework (where the recipient is certified) or Standard Contractual Clauses.
  • How we handle visitors' data: see the privacy notice.

05Security

We are early-stage. None of the controls below is confirmed as live yet, so we list all of them as planned before first delivery and will move each to "in place" only once it is.

Planned before first delivery

  • Single sign-on and multi-factor authentication on all company accounts
  • Encryption in transit and at rest; EU storage region
  • Least-privilege access, access logging, quarterly access review
  • Separate storage per buyer; no buyer data mixed across projects
  • Encrypted, company-managed capture devices; footage offloaded and wiped daily
  • Written incident-response plan

Certifications: none yet. We follow a SOC 2 / ISO 27001 readiness roadmap and will pursue SOC 2 Type I first if a buyer requires it. We complete buyer security questionnaires.

06Honest status

  • No environment has been built or delivered yet.
  • No video has been captured.
  • No customers yet.
  • Consent pack, DPA and security documents are drafts awaiting legal review.

We say this up front because a supplier that overstates its status once can't be trusted on provenance.

07Illustrative visuals

The diagrams and visuals on this website are illustrations. They don't show real venues, real people, real captured streams, our environments' final interfaces or any captured data.

08Contact

Security and privacy questions: Ramon Sicre, Sicreto Labs LLC, hello@sicreto.ai or LinkedIn.