Privacy Policy

Last Updated: April 25, 2026

Data CollectionAI Data UsageGDPR & DPASecurityRetention

1. Our Commitment to Privacy

At AuditSentinel, we recognise that financial data is among the most sensitive information an enterprise handles. Our privacy framework is built on the principle of Data Minimisation: we only collect what is strictly necessary to perform your audit, and we keep it for the shortest time possible.

2. Data Ingestion & Collection

We process two categories of data with a strict focus on privacy from the first byte:

  • Account Data: Name, work email, and organisation details used for authentication and billing.
  • Audit Data: Transactional data extracted from uploaded bank statements and CSV files. Raw CSV files are processed in-memory, scrubbed for PII (Personally Identifiable Information) at the browser level, and never stored permanently in their raw form. We only extract what is necessary for classification (vendor names, amounts, and dates).

3. AI Processing & Non-Training

AuditSentinel utilises Enterprise-grade AI via Anthropic (Claude). Transaction data is sent to Claude for classification purposes only.

  • Zero-Training Guarantee: Your data is processed via API endpoints that explicitly prohibit the use of customer data to train global AI models.
  • Contextual Isolation: Data is sent for classification in isolated sessions and is not "remembered" or stored by the AI models after processing is complete.

4. GDPR / UK GDPR Compliance & Your Role

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR), the following roles apply when you use the AuditSentinel platform:

  • You (the Customer) act as the Data Controller. You determine the purpose and means of processing the personal data contained within your uploaded financial records.
  • AuditSentinel acts as the Data Processor. We process personal data solely on your documented instructions for the purpose of delivering the audit, classification, and reporting services.

Our Data Processing Agreement (DPA), which incorporates the Standard Contractual Clauses (SCCs) where applicable, is available for download and forms part of these Terms. Download the DPA (PDF).

The lawful basis for processing is Legitimate Interest (delivery of contracted audit services) and, where applicable, Consent. You warrant that you have the appropriate lawful basis to share any personal data contained within uploaded materials with AuditSentinel as your processor.

5. Data Security & Storage

Your data is hosted on SOC2 Type II compliant infrastructure managed by Supabase (AWS). All data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Database access is restricted via Row-Level Security (RLS) to ensure that only authorised members of your organisation can view your audit results.

6. Data Retention & One-Click Deletion

We do not believe in permanent storage of sensitive financial documents. Raw bank statements are held in temporary, encrypted volatile memory during processing and are automatically purged from our systems within 24 hours.

Processed audit findings are retained only as long as your user account is active. Users maintain full control over their data; you can delete your entire audit history at any time with a single click. Once deleted, this data is scrubbed from our active databases immediately.

7. Contact Us

For any privacy-related inquiries or to request data deletion, please contact our Data Protection Officer at security@auditsentinel.app.

AuditSentinel

Architecting financial transparency for the Generative AI era. Built on 15+ years of enterprise engineering excellence.

Privacy Matters

AuditSentinel is built on trust. Our website uses Umami Analytics, a privacy-focused, cookieless platform. We don't use tracking cookies, we don't collect PII, and we don't follow you around the web.

Learn more in our full Privacy Policy →

Platform

  • Executive Dashboard
  • AI Audit Engine
  • Insights Vault
  • Enterprise Pricing

Trust & Security

  • Security & Trust Center
  • Privacy Policy
  • Terms of Service
  • DPA (Data Processing)
AES-256 Encrypted
Zero-Training AI

Company

  • About the Founder
  • Contact Security
  • System Status

FREE UTILITIES

  • ISO 42001 Toolkit
  • AI Policy Builder
  • Shadow AI Cost Calculator
  • AI Governance Maturity Quiz
  • AI Tool Directory

COMPARE

  • AuditSentinel vs Vanta
  • AuditSentinel vs Drata
  • AuditSentinel vs OneTrust
  • AuditSentinel vs Zylo
  • AuditSentinel vs BetterCloud
  • AuditSentinel vs Torii

© 2026 AuditSentinel. All rights reserved.

Built in Leeds, UK|v1.2.0