Safety · Data security & models
Your content trains your rulesets. Nothing else.
Everything you send Typetone stays yours: isolated per customer, encrypted end to end, never used to train a shared model. IT gets a system to review, not a data-transfer negotiation.













Today
The three questions IT asks before anything gets signed.
Marketing wants the audit. Security wants to know exactly what leaves the building, where it lands, and who can see it.
Where does the content actually go?
Most AI tooling is vague about it: which region, which subprocessors, how long anything is retained. Vague answers stall procurement for months.
Does it train someone else's model?
Your product copy, your unpublished campaigns and your compliance rulebook are competitive IP. Pasting them into a shared model gives that away quietly.
Who can see what, internally?
An audit surfaces every violation in the business. Without real role-based access that becomes a company-wide list of everything you got wrong.
Answers your security team can actually check.
Your content stays your IP
Content, rulesets and outputs remain fully owned by you. Nothing is used to train a shared or general-purpose model, and nothing is reused across customers.
Isolated and encrypted
Tenant isolation per customer, with AES-256 encryption at rest and in transit. Security controls are audited by an independent third party.
Access you control
Enterprise authentication with granular role-based access, so legal, brand and market teams each see their own scope — and every action is logged.
The engine
What happens to a document, end to end.
Content arrives through your CMS, DAM or PIM, by upload, or by crawling what you already publish. It lands in your tenant, not in a shared pool.
Assets are checked against your rulesets on EU infrastructure. Models are used to evaluate and rewrite — never to learn from your data for anyone else's benefit.
You decide what is kept and for how long. Findings, versions and approvals stay available as evidence; delete a workspace and its content goes with it.
Generic AI tooling versus Typetone
Before — do it yourself
Shared
models, fed whatever anyone pastes in
Unclear retention, unclear region, and your unpublished campaigns in someone else's training set.
After — with Typetone
Isolated
per customer, and never used for training
Encrypted, role-scoped and logged, on European infrastructure.
Also in Safety
The rest of the trust picture
Where the platform runs, which regulations it enforces, and the legal documents behind both.
Questions
Frequently asked questions
Do you train models on our content?
No. Your content, rulesets and outputs are never used to train a shared or general-purpose model, and nothing is reused across customers. Models are used to evaluate and rewrite your assets within your own tenant.
Where is our data processed and stored?
On European infrastructure, in the EU. The specific regions and the current subprocessor list are provided as part of the data processing agreement — ask for them during the security review and they'll be shared in writing.
How is access controlled?
Enterprise authentication with granular role-based access control at organisation level, so each team only sees its own scope. Every check, change and approval is recorded with the person and timestamp behind it.
What happens if we leave?
You keep full ownership of everything you put in and everything that comes out. Content and rulesets can be exported, and deleting a workspace removes its content on the agreed retention terms.
Are your security controls audited?
Yes — security controls are audited by an independent third party and aligned with industry standards. Ask for the current attestation and control documentation during procurement; it is shared under NDA rather than published.
Go deeper
Keep reading
Built in the EU
European technology on EU servers, GDPR-compliant by default — and what that means for procurement and data residency.
See the pageLegal & compliance officers
How the audit trail works from the compliance side: one ruleset, enforced everywhere, with defensible evidence behind every check.
See the role page