Security & Trust
How TrackLock handles your music and data today, stated plainly — including what's still in progress.
Encryption
Data is encrypted in transit via TLS. Encryption-at-rest for stored audio and metadata is planned as the platform moves toward production deployment.
Private storage
Uploaded audio is stored per-organization and is not made public. Only the public-safe fields shown on a rights-check page (title, artist, verification level, AI-use status) are ever exposed without authentication.
Audit history
Every registration, policy change, verification decision, and license event is recorded in an audit log tied to the asset it affects.
Data retention
Registered assets and their audit history are retained for as long as your account is active. Formal retention and deletion policies are being finalized ahead of general availability.
Access controls
Actions are scoped to your organization and role — viewing, editing, and administrative actions each require the appropriate membership level.
No sale of uploaded masters
TrackLock does not sell, license, or otherwise distribute your uploaded audio to third parties. Audio is used only to generate fingerprints and check matches.
How matching works
Uploaded audio is compared against registered assets using audio fingerprinting, not manual listening. A match produces a confidence score, not an automatic legal conclusion.
Limitations
No fingerprinting system detects every possible transformation, and no automated decision replaces human judgment in a dispute. See our Product Limitations page for specifics.
TrackLock does not currently hold SOC 2, ISO 27001, or other third-party security certifications.