AIPWN / TRUST BOUNDARIES
Security & data handling
Different tools handle different data. This page shows where inputs go, what AIPwn stores, and which third parties participate.
Data paths
How inputs are handled
Browser-local C2PA check
The selected image is processed in your browser and is not uploaded to AIPwn.
Cloud image declaration reading
AIPwn reads C2PA and IPTC metadata from submitted image bytes. The database keeps digests, declaration findings and report metadata, not raw images or source URLs. The server does not verify C2PA signatures.
Agent Security evaluation
AIPwn masks well-formed secret literals before sending content to TypeSafe for semantic signals. AIPwn's rules and policy engine produce advisory decisions. AIPwn does not persist raw prompts, tool arguments, outputs or traces.
Providers
Third-party services
Cloudflare
Site, API and account database hosting
TypeSafe
Processes redacted Agent Security input and returns semantic signals; its retention terms are separate from AIPwn's
Stripe
Processes checkout and billing details when you top up
Google / GitHub
Supplies account profile data only when you choose that sign-in method
Google Analytics
Receives optional public-page analytics only after consent; disabled on detector, Console and report pages
AIPwn's zero-raw-retention statement applies to AIPwn storage. Providers such as TypeSafe handle data under their own terms.
Controls
Your data controls
Export or delete account data in the Console. The Privacy Policy describes data categories, cookies and deletion scope in full.