Your catalog, your metadata and every piece of enforcement evidence are handled under strict access controls - because a claim is only as strong as the evidence behind it.
Catalog data, evidence and account traffic are encrypted in transit (TLS) and at rest. Credentials are stored hashed, never in plain text.
Role-based access scoped per catalog and per client. Analysts see the cases they work on - not your whole business. Access is reviewed and revoked on role change.
Sign-ins, views, approvals, filings - every action is logged with actor and timestamp into an append-only case history that backs up every claim we make on your behalf.
Detection runs on derived fingerprints, not on circulating copies of your audio. Source files are handled only as your contract specifies, and only for the purposes it names.
Takedown power comes from statute. Using it carelessly puts your claims - and your standing with platforms - at risk. So the legal discipline is built into the product.
Notices meet the elements of 17 U.S.C. §512(c)(3), are sent only on verified evidence with your recorded authorization, and counter-notices are honored through the process described in our Counter-Notice Policy.
In the EU we follow the DSA's notice-and-action framework - substantiated notices, statements of reasons, and respect for the dispute channels platforms must provide.
Personal data is processed as described in our Privacy Policy. Access, correction and deletion requests go to privacy@sonproof.com and are handled within statutory timelines.
No enforcement action is ever fired by a machine alone. Human verification plus your approval is our standing safeguard against misrepresentation - the risk §512(f) exists to punish.
Security researchers who report vulnerabilities in good faith to security@sonproof.com get a fast human response, a fix timeline, and our thanks. We do not pursue good-faith research.
Bring your security and legal teams to the demo - custody, access, audit and compliance are exactly what we like being asked about.