Trust center

Security and compliance

Everything your lawyer, DPO or board will ask about — on a single page. Send them the link and get back to building your product.

Privacy in the architecture, not in promises

Images never stored

We process the uploaded image in memory only for the duration of inference and delete it immediately afterward. It never touches disk. We log only metadata: time, result, file size — from which the image can't be reconstructed.

Data stays in the EU

The entire processing infrastructure runs in the European Union. Zero transfers to third countries — you don't need contractual clauses or transfer assessments, because there simply is no transfer.

Self-hosting: data never leaves at all

For sensitive sectors and strict requirements: our container runs on your infrastructure, and images never leave it. Let's talk →

GDPR

Clear division of roles

When we process images on your behalf, we act as a data processor — you remain the data controller for your users' data. For your account and billing data, we are the controller.

DPA as standard

You sign the Data Processing Agreement with us right away — in Polish, without six months of negotiations. You'll find the template in the legal section, and accepting it is part of registration.

Data minimization

We store only what's necessary to run the service and handle billing: email, invoice details and API usage metadata. No advertising tracking, no selling data to anyone.

Data subject rights

Access, rectification, erasure, restriction, portability, objection — we handle these in line with the GDPR and help you fulfill these rights toward your users. Details in the Privacy Policy.

DSA — due diligence you can demonstrate

Immutable audit log

Every moderation decision goes into a hash-chained log — it can't be silently altered or wiped. When a regulator or court asks "what, when and why", you have the answer ready.

Human in the loop

Borderline cases go to the human-in-the-loop queue, and moderator decisions are recorded. The DSA expects explainable decisions — that's exactly what you get.

Reporting mechanism

A reactive layer: user reports (/v1/report) escalate content for re-evaluation. Your obligation to act on reports is covered by a single endpoint.

modwall is an assistive tool — it doesn't "handle compliance" for you and doesn't make the final decisions on your behalf. What it does give you are the processes and records that the DSA expects from a platform operator.

Technical security

  • Transmission over HTTPS/TLS only.
  • API keys are stored as hashes — you see the full key only once, at creation.
  • Public widget keys restricted to a list of authorized domains (Origin verification).
  • Webhooks signed with HMAC (X-Modwall-Signature) — you know it's from us.
  • Separation of key roles: server keys (secret) vs. widget keys (public).
  • Payments are handled by the licensed operator Przelewy24 — we never touch card data.

The limits of the service — we're upfront about them

Image detection scope: NSFW (nudity / adult content), weapons, and violence/gore (beta) — the client enables each category deliberately, per profile. We don't detect offensive gestures or symbols. The text model scores the toxicity of a message. A score is a probability estimate, not a verdict — the final decision and responsibility for content remain with the client.

CSAM material is out of scope for the service — it's a separate, regulated ecosystem based on hash-matching and mandatory reporting obligations. Honest boundaries are part of compliance too.

Documents: Terms of Service · Privacy Policy · Data Processing Agreement (DPA)

Questions from a lawyer or DPO?

We give specific answers, in Polish. And if the requirement is "data must not leave our infrastructure" — we have self-hosting.

Contact us Create a free account