Content submitted for analysis is among the most sensitive data a platform can hand to a vendor. This page summarizes how Visork handles it. The contractual versions of these commitments live in the Data Processing Agreement — this page is the readable summary; the DPA is what you sign.
What happens to submitted content
Analysis runs entirely in volatile memory (RAM): submitted media is never written to disk for the purpose of the analysis itself. By default, content is deleted promptly after the verdict returns. Anything that is retained — the cases below — is a separate, explicit step that happens after the analysis, never a side effect of it.
Training is off by default
By default, customer content is not used to train, fine-tune, or evaluate our models, and we build no profiles from it. Detection models are developed on lawfully obtained datasets in cooperation with law-enforcement authorities — not on your traffic.
Training on customer content happens only when a customer explicitly enables it: through an individual written agreement (covering a general or a customer-specific model) or through the service settings. Where a free tier is offered, its defaults may differ — retention and training use may be enabled by default, stated at sign-up, and can be switched off in the settings at any time. Paid tiers always default to off.
Confirmed findings become hashes
When an analysis flags content as likely harmful, the flagged item may be retained for confirmation by a small number of authorized reviewers bound by confidentiality. Only when a human confirms the material as harmful is a perceptual hash derived — a numerical fingerprint that lets the service recognise the same or visually similar material on re-encounter, but cannot be reversed back into the image. The hash database serves the service as a whole: material confirmed once is caught faster wherever it reappears. No hash is ever stored on an automated verdict alone.
Evidence preservation
Where the outcome of an analysis or the legal qualification of the content justifies it, flagged content and its associated metadata may be preserved (archived) so that competent public authorities are able to act — and where the law or a binding order requires preservation, disclosure, or reporting, we comply. The contractual wording is in the DPA (Section 13).
Where retained content lives
Anything retained after analysis — flagged items pending review, preserved evidence, or content stored under an agreed configuration — stays in the EU on dedicated storage infrastructure held to heightened security standards: not directly reachable from the public internet, accessed exclusively over an encrypted internal protocol, and encrypted at rest.
What does persist
Detection results and audit-log entries — score, threshold, verdict, module — are retained for the term of the agreement or as you configure. They never contain the submitted media. Perceptual hashes of human-confirmed material persist for as long as they serve detection. Aggregated, de-identified service telemetry (request volumes, latency, error rates, score distributions) contains no customer personal data.
EU residency
Inference, transient storage, and audit logs for API content stay in the EU. This is the standard deployment, not an enterprise add-on: data residency is scoped per platform only when a customer needs something stricter, not to unlock EU processing.
Security measures
The measures below are the current technical and organizational measures from the DPA (Annex 2):
- Encryption in transit and at rest. TLS 1.2 or higher on every connection; analysis in volatile memory; encryption at rest for anything retained after analysis.
- Least-privilege access. Access on a need-to-know basis, with multi-factor authentication required for administrative access.
- Segmented environments. Network segmentation and firewalling between environments — the inference path is not reachable from anything that does not need it.
- Logging and audit trails. Processing operations and administrative access are logged and monitored alike.
- Vulnerability management. Timely security updates, secure development practices, and periodic review of the measures themselves.
- Incident response. A documented incident-response process, with customer notification within 48 hours of becoming aware of a breach affecting customer data.
Documented for your DPO
- Trust & security overview — the summary a customer forwards to their DPO.
- Data Processing Agreement — published in full, including the sub-processor list; countersigned copies are issued as part of commercial agreements.
- Trust portal — security documentation, questionnaires, and pentest reports.
- Responsible disclosure — security@visork.com,
published at
/.well-known/security.txt.