Trust
Scope security controls to the actual data flow
Audiencelab security review starts with the proposed implementation: systems, data categories, identifiers, regions, retention, subprocessors, access, and incident contacts. This public page does not claim certifications or controls that have not been independently documented.
Overview
01Data minimization
Use only the fields required for the declared measurement and activation purpose. Avoid user-level identifiers where the workflow does not require them.
02Access and integration review
Document credentials, permissions, environments, owners, rotation, and revocation for every source and destination.
03Customer diligence
Detailed architecture, subprocessors, retention, and contractual controls should be reviewed through the customer security process for the intended deployment.
Process
- Map systems and data categories
- Confirm purpose and minimum fields
- Review access, retention, and regions
- Test the approved implementation
- Maintain owners and incident contacts
Limitations
What this page does not prove or guarantee.
- This overview is not a certification, audit report, or legal opinion.
- Controls and obligations depend on the customer's implementation.
- Do not infer a compliance status that is not explicitly documented.
Questions
- Does this page claim SOC 2 or ISO certification?
- No.
- Where is the privacy policy?
- The public privacy policy is available at audiencelab.ai/privacy.
- How do I request a security review?
- Contact support@audiencelab.ai with the intended deployment scope.