AIPWN / TRUST BOUNDARIES

Security & data handling

Different tools handle different data. This page shows where inputs go, what AIPwn stores, and which third parties participate.

How inputs are handled

Browser-local C2PA check

The selected image is processed in your browser and is not uploaded to AIPwn.

Cloud image declaration reading

AIPwn reads C2PA and IPTC metadata from submitted image bytes. The database keeps digests, declaration findings and report metadata, not raw images or source URLs. The server does not verify C2PA signatures.

Agent Security evaluation

AIPwn masks well-formed secret literals before sending content to TypeSafe for semantic signals. AIPwn's rules and policy engine produce advisory decisions. AIPwn does not persist raw prompts, tool arguments, outputs or traces.

Third-party services

Cloudflare

Site, API and account database hosting

TypeSafe

Processes redacted Agent Security input and returns semantic signals; its retention terms are separate from AIPwn's

Stripe

Processes checkout and billing details when you top up

Google / GitHub

Supplies account profile data only when you choose that sign-in method

Google Analytics

Receives optional public-page analytics only after consent; disabled on detector, Console and report pages

AIPwn's zero-raw-retention statement applies to AIPwn storage. Providers such as TypeSafe handle data under their own terms.

Your data controls

Export or delete account data in the Console. The Privacy Policy describes data categories, cookies and deletion scope in full.