Scope and deployment
The production domain, GitHub repository, and deployed commit must be linked with observable evidence.
TrustData AI Standard v1.0
TrustData Verified means seven required controls passed with fresh, observable evidence. It is not a legal, government, GDPR, SOC 2, or ISO certification.
The production domain, GitHub repository, and deployed commit must be linked with observable evidence.
AI providers, SDKs, models, and endpoints used by the product are detected and inventoried.
AI keys must remain server-side, no secret may be exposed, and observable storage parameters must satisfy the standard.
The applicable public retention and training policy is mapped to each detected endpoint with a version and observation date.
Row-level security, public buckets, functions, and schema exposure are checked against the declared production scope.
A working retention, deletion, or anonymization mechanism must be observable in code or provider configuration.
Relevant webhooks must be signed and no unresolved critical security finding may remain.
Evidence provenance
TrustData stores bounded metadata, fingerprints, paths, rules, and strongly redacted excerpts. It never retains complete repositories, credentials, customer records, prompts, or production content.
Founder declarations
The onboarding questionnaire identifies systems, policies, and expected behavior, then surfaces contradictions with observed evidence. A declaration cannot make a control pass and remains clearly separated from technical evidence.
Status lifecycle
All seven controls passed and every required source remains fresh.
At least one required control failed or still needs observable evidence.
A required source remained inaccessible beyond its 72-hour grace period.
A confirmed critical issue, fraud signal, or compromise made the public badge inactive.