Trust & governance

Compliance your general counsel can sign.

Pureset is built for procurement review: audited controls, documented rights and contractual guarantees that survive due diligence.

Certifications & guarantees

Controls, audited. Rights, guaranteed.

SOC 2 Type II

Audited controls across security, availability and confidentiality, attested by an independent auditor.

Report available under NDA

ISO/IEC 27001

Certified information security management covering ingestion, storage and delivery infrastructure.

Certificate IS-XXXXXX · annual surveillance

Clean lineage & chain-of-custody

A signed provenance ledger accompanies every shard, with notarized custody hand-offs end to end.

100% record coverage · independently audited

Legal indemnification

Enterprise licenses include infringement indemnification and complete rights-clearance documentation.

Included in all enterprise terms

The Clean Lineage Guarantee

If a record's provenance cannot be sealed — every hand-off accounted for, every right cleared — it never enters your corpus. No exceptions, no “best effort”.

Request the provenance whitepaper
How we govern data

Six commitments, documented.

Each commitment below is backed by evidence that ships with your data or is available to your security and legal teams under NDA.

Provenance & chain of custody

Every record carries its origin: the archive or contributor it came from, its capture date and the license it was acquired under. Each hand-off — from archive to digitization partner to our pipeline to your bucket — is signed into a provenance ledger.

  • Capture certificates issued at the point of origin
  • Signed, notarized custody hand-offs
  • Per-shard SHA-256 seals you can verify independently
  • Records that can't be sealed never enter a corpus

Licensing & rights

Sources are licensed, in the public domain or commissioned under contract — and rights are cleared and documented before a single token is ingested.

  • License class recorded per record and per slice
  • Rights-clearance documentation with every release
  • Infringement indemnification in enterprise terms
  • A takedown and re-release process for disputed records

Privacy & PII

Human data means personal data can appear. Pureset detects and scrubs it, then has human reviewers check audited samples before anything ships.

  • Automated detection of names, contact details and identifiers
  • Human review of audited samples in every release
  • PII results published in each quality report
  • GDPR-ready data processing addendum

Bias methodology

Bias isn't removed by assertion. We measure source, era, region and demographic distributions against documented baselines, rebalance where needed and publish the result.

  • Documented baselines for every collection
  • A rebalancing report shipped with each slice
  • Distribution drift monitored across versions
  • Known limitations disclosed in every data card

Security

Licensed corpora and customer information are protected by audited controls across ingestion, storage and delivery.

Found a vulnerability? Email security@pureset.ai. We acknowledge reports within two business days and never pursue good-faith research.

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Least-privilege staff access with SSO and MFA
  • US and EU data residency options
  • Annual third-party audits and penetration tests

Responsible use policy

Clean data should build useful, safe systems. Licensed Pureset data may not be used for the purposes listed here. Violations are grounds for license termination, and the full policy is part of every enterprise agreement.

  • Identifying, tracking or profiling individuals
  • Generating deceptive content or impersonating real people
  • Unlawful surveillance or discrimination
  • Re-identifying people from de-identified records

Need the paperwork?

Request our audit reports, security questionnaire responses, data processing addendum and provenance whitepaper — shared under NDA.