Security, Moderation & Trust

Classifier-based content moderation with human review of abuse reports, granular GDPR & KVKK controls, encrypted bring-your-own-key vaults, tamper-evident hash-chained billing audit records, and a full on-prem option. Trust isn't a checkbox here - it's the architecture.

Trust, built into the architecture - not bolted on

Most platforms treat security and compliance as a settings page. We treat them as load-bearing walls. Every AI call is itemized and written to a tamper-evident record, uploaded images and publicly shared text are screened before they go live, every byte of your data is yours to export or erase - and when the cloud isn't an option, the whole platform runs on your own hardware, against your own models.

Talk to us about enterprise & on-prem · Read the security overview


Moderation with a human in the loop

Bad content doesn't wait for business hours. Automated moderation runs a content classifier over the images you upload - screening them before they are stored and rejecting anything it flags, including sexual content involving minors - and over the text you publish to public surfaces like shared canvas artifacts and community and forum posts, screening it before it goes live. Public persona content is held until it reaches an approved state.

To be clear about what this is and isn't: screening is a classifier applied to uploaded images and public text - not a hash-matching database like PhotoDNA - and it does not cover every private, in-session generation. Coverage is expanding over time.

CSAM and other illegal content are prohibited by our Acceptable Use Policy. When we become aware of such content we remove it, terminate the account, and report it to the competent authorities where the law requires - a policy commitment, not an automated reporting pipeline.

When the platform gets a call wrong, or a user sees something they shouldn't have, people aren't stuck. Abuse reports let anyone flag content for human review; enforcement is proportionate - a warning, a suspension, or termination - and an appeal gives the affected user a formal path to contest the outcome.

  • Classifier screening before publish - uploaded images are checked before storage; text bound for public surfaces is checked before it goes live.
  • Human review of abuse reports - flagged content is reviewed by a person, with proportionate enforcement, never a silent black box.
  • Honest about coverage - a classifier over uploaded images and public text, not a PhotoDNA-style hash database, and not every private generation. We say so plainly.

Your data, your rules - GDPR & KVKK first-class

Privacy here isn't an "accept all" banner. Consent is tracked per category - marketing, analytics, personalization - each with its own version history and a clean revoke trail. When a user asks for their data, the request is a first-class object: we generate the export, schedule the erasure, and notify them when it's done. Erasure does the right thing per data type - content is hard-deleted, while financial and audit records are anonymized and retained, because the law requires both.

Whether you answer to the GDPR, Turkiye's KVKK, or an internal auditor, the paperwork is already done - because the platform produces it automatically.

  • Data-subject requests - formal access, portability, and erasure flows that run end-to-end across modules, not a support ticket.
  • Granular consent - opt in or out per category, with full revoke history. No more all-or-nothing toggles.
  • Retention you control - per-entity retention policies so data lives exactly as long as it should, and no longer.

Zero-knowledge keys and a tamper-evident record

Bring your own provider keys and we'll route your AI calls through them - but we never see them decrypted. Credentials sit encrypted at rest in a per-tenant vault and are never exposed in plaintext to the platform.

Under the billing layer sits a hash-chained audit of billing records: every AI call writes exactly one immutable billing record with a full pricing snapshot, and each record is cryptographically linked to the one before it, so tampering is mathematically detectable. A nightly job re-walks the chain and raises the alarm if a single record has been altered. For a bank or a regulator, that's the difference between "trust us" and "verify it yourself."

  • Encrypted BYOK vault - your provider keys, encrypted at rest, never exposed in plaintext to the platform.
  • Hash-chained billing audit - a tamper-evident, append-only history of every priced AI call, verified nightly by an integrity check.
  • A price on every call - one immutable record per AI call, with the exact model, capability, and rate it ran at.

When the cloud isn't an option, run it yourself

Some industries can't send data anywhere - and for them, ToRun ships as a full on-premise deployment. One command spins up the entire platform on your own hardware, inside your own network, pointed at your own local models so no prompt or document ever leaves your walls. The billing audit trail stays tamper-evident under your control, and your auditors can inspect the running system directly.

For the most regulated environments, a source-code license puts the platform's code in your hands - perpetual, unlimited internal seats - paired with an ongoing Platform Evolution subscription so new models, providers, and security hardening keep flowing in. A signed auto-update channel keeps you current without a migration project, and optional source-code escrow gives you continuity guarantees on top.

  • Full on-prem deployment - the complete platform in your own VPC or data center, on your own models. Zero data leakage by design.
  • Source-code license - perpetual code access for banks and regulated industries, with bundled architect advisory.
  • Escrow & continuity - optional source escrow so your operation is protected no matter what happens upstream.

The full on-prem story - local LLMs, one-command install, licensing tiers - is on the On-Prem & Self-Hosted page.


Highlighted capabilities

  • Classifier moderation + human review a content classifier screens uploaded images and public text before publish; abuse reports get human review, not a black box.
  • CSAM prohibited & reported illegal content is banned by our Acceptable Use Policy; on discovery we remove it, terminate the account, and report to the authorities where required.
  • GDPR & KVKK requests access, portability, and erasure as first-class flows. The export is generated and the erasure scheduled automatically.
  • Granular consent opt in or out per category, each with full version and revoke history.
  • Zero-knowledge BYOK vault your provider keys stay encrypted at rest and never seen in plaintext to the platform.
  • Hash-chained billing audit a tamper-evident, append-only record of every priced AI call. A nightly integrity check re-walks the chain and flags any alteration.

Built for the audits you hope you never have

From a startup's first compliance review to a bank's regulatory inspection, the platform is ready before the auditor walks in.

Talk to our team · Explore enterprise plans

Trust architecture: classifier-based content moderation that screens uploaded images before they are stored and public text before it goes live — not a PhotoDNA hash-matching database — over an encrypted BYOK vault foundation.
Back to all features