The page you forward to your DPO.
How Visork handles the most sensitive category of content on the internet — what we keep and when, where it runs, and what you can verify before a single image is sent.
Hold as little as possible, as briefly as possible.
The pipeline is built around one principle: the content we analyse is the last thing we want to store. What follows is the exact split between what disappears and what remains, as committed in the DPA.
Analysed in RAM, deleted by default
Analysis runs entirely in volatile memory — media is never written to disk to be analysed. By default it is deleted promptly after the verdict; retention is an explicit post-analysis step, never a side effect.
Training off by default
Customer content is not used to train or fine-tune models unless a customer explicitly enables it — by written agreement or in the service settings. Paid tiers always default to off; where a free tier is offered, its defaults may differ and are stated at sign-up. Detection models are developed on lawfully obtained datasets in cooperation with law enforcement.
Confirmed findings become hashes
Content flagged as likely harmful may be held for review by a small number of authorized reviewers. Only material a human confirms is fingerprinted with an irreversible perceptual hash, so known material is caught faster across the service.
Evidence preservation
Where the legal qualification of a finding justifies it, flagged content and its metadata may be preserved so competent authorities can act — and where law or a binding order requires preservation or reporting, we comply.
Isolated storage for what's retained
Anything retained after analysis lives in the EU on dedicated storage with no direct reachability from the public internet, accessed exclusively over an encrypted internal protocol and encrypted at rest.
What does persist
Detection results and audit-log entries — score, threshold, verdict, module — are retained for the term of the agreement or as you configure. They never contain the submitted media.
The controls behind the API.
A summary of the technical and organizational measures from Annex 2 of the DPA. The DPA is the contractual source — if this page and the DPA ever disagree, the DPA wins.
Encryption in transit and at rest
TLS 1.2 or higher on every connection; encryption at rest for any transient storage used during processing.
Least-privilege access
Access on a need-to-know basis, with multi-factor authentication required for administrative access.
Segmented environments
Network segmentation and firewalling between environments — the inference path is not reachable from anything that doesn't need it, and retained content sits behind an encrypted internal protocol with no direct internet reachability.
Everything logged
Logging, monitoring, and audit trails cover processing operations and administrative access alike.
Vulnerability management
Timely security updates, secure development practices, and periodic review of the measures themselves.
Incident response
A documented incident-response process, with customer notification within 48 hours of becoming aware of a breach affecting customer data.
EU for the sensitive path. Documented for the rest.
Data residency claims tend to blur the line between the product and the website. Here it is drawn explicitly, because your DPO will ask.
The API path — EU only
Customer content submitted to the API is processed on cloud infrastructure located in the European Union: inference, transient storage, and audit logs. Provider details are available on request at hello@visork.com and will be published in the DPA before general availability of the API.
This website — Vercel, PostHog and Cookiebot
The marketing site is delivered by Vercel Inc. (USA), safeguarded by the EU–US Data Privacy Framework and Standard Contractual Clauses. Site analytics is PostHog, stored in Frankfurt on its EU cloud, and it loads only if you opt in through our banner — served, and its record kept, inside the EU by Cookiebot (Usercentrics A/S, Denmark). Those two are the only third-party components the site loads, and it loads them directly: Google Analytics and Google Tag Manager were both removed, so no tag platform can add a third. Decline and nothing is stored in your browser beyond your theme preference and that refusal.
Any addition or replacement of a sub-processor is announced at least 14 days in advance, with the right to object. The authoritative list lives in Annex 3 of the DPA.
What's published, what's signed, what's next.
No certification is claimed here that doesn't exist yet. This is the current state; the order it changes in is shaped by what pilot platforms actually need first.
Published in full; countersigned copies are issued as part of commercial agreements.
security@visork.com, published at /.well-known/security.txt.
Security documentation, questionnaires, and pentest reports at trust.visork.com.
Lands as part of commercial agreements, shaped with the first pilot platforms.
Planned for the enterprise-readiness phase — after pilots prove the product, not before.
Security reports go to security@visork.com — the address is published in security.txt, and reports are read by the person who can actually fix the issue.
Questions that survived this page?
The DPA, the privacy policy, and this overview are written to be forwarded. Whatever they don't answer belongs on the scoping call — we'd rather resolve it before integration than after.