TrustData AI Standard v1.0

A current technical result with every source exposed.

TrustData Verified means seven required controls passed with fresh, observable evidence. It is not a legal, government, GDPR, SOC 2, or ISO certification.

01

Scope and deployment

The production domain, GitHub repository, and deployed commit must be linked with observable evidence.

02

AI provider inventory

AI providers, SDKs, models, and endpoints used by the product are detected and inventoried.

03

AI keys and storage

AI keys must remain server-side, no secret may be exposed, and observable storage parameters must satisfy the standard.

04

Provider policies

The applicable public retention and training policy is mapped to each detected endpoint with a version and observation date.

05

Supabase isolation

Row-level security, public buckets, functions, and schema exposure are checked against the declared production scope.

06

Retention and deletion

A working retention, deletion, or anonymization mechanism must be observable in code or provider configuration.

07

Application security

Relevant webhooks must be signed and no unresolved critical security finding may remain.

Evidence provenance

A conclusion never hides where it came from.

TrustData stores bounded metadata, fingerprints, paths, rules, and strongly redacted excerpts. It never retains complete repositories, credentials, customer records, prompts, or production content.

Observed in code
Produced by deterministic static analysis of the selected repository and commit.
Observed from provider
Retrieved from an authorized Vercel, Supabase, or other supported provider connection.
Derived from public policy
Mapped to a detected AI endpoint from a versioned OpenAI or Anthropic public policy.
Not observable
A setting or account override is not exposed by code or a supported API, so TrustData makes no claim about it.

Founder declarations

Useful for scope. Never proof for the badge.

The onboarding questionnaire identifies systems, policies, and expected behavior, then surfaces contradictions with observed evidence. A declaration cannot make a control pass and remains clearly separated from technical evidence.

Status lifecycle

Verified

All seven controls passed and every required source remains fresh.

Action required

At least one required control failed or still needs observable evidence.

Expired

A required source remained inaccessible beyond its 72-hour grace period.

Suspended

A confirmed critical issue, fraud signal, or compromise made the public badge inactive.