Last Updated: April 25, 2026
At AuditSentinel, we recognise that financial data is among the most sensitive information an enterprise handles. Our privacy framework is built on the principle of Data Minimisation: we only collect what is strictly necessary to perform your audit, and we keep it for the shortest time possible.
We process two categories of data with a strict focus on privacy from the first byte:
AuditSentinel utilises Enterprise-grade AI via Anthropic (Claude). Transaction data is sent to Claude for classification purposes only.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR), the following roles apply when you use the AuditSentinel platform:
Our Data Processing Agreement (DPA), which incorporates the Standard Contractual Clauses (SCCs) where applicable, is available for download and forms part of these Terms. Download the DPA (PDF).
The lawful basis for processing is Legitimate Interest (delivery of contracted audit services) and, where applicable, Consent. You warrant that you have the appropriate lawful basis to share any personal data contained within uploaded materials with AuditSentinel as your processor.
Your data is hosted on SOC2 Type II compliant infrastructure managed by Supabase (AWS). All data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Database access is restricted via Row-Level Security (RLS) to ensure that only authorised members of your organisation can view your audit results.
We do not believe in permanent storage of sensitive financial documents. Raw bank statements are held in temporary, encrypted volatile memory during processing and are automatically purged from our systems within 24 hours.
Processed audit findings are retained only as long as your user account is active. Users maintain full control over their data; you can delete your entire audit history at any time with a single click. Once deleted, this data is scrubbed from our active databases immediately.
For any privacy-related inquiries or to request data deletion, please contact our Data Protection Officer at security@auditsentinel.app.