Security & Trust

How TrackLock handles your music and data today, stated plainly — including what's still in progress.

Encryption

Data is encrypted in transit via TLS. Encryption-at-rest for stored audio and metadata is planned as the platform moves toward production deployment.

Private storage

Uploaded audio is stored per-organization and is not made public. Only the public-safe fields shown on a rights-check page (title, artist, verification level, AI-use status) are ever exposed without authentication.

Audit history

Every registration, policy change, verification decision, and license event is recorded in an audit log tied to the asset it affects.

Data retention

Registered assets and their audit history are retained for as long as your account is active. Formal retention and deletion policies are being finalized ahead of general availability.

Access controls

Actions are scoped to your organization and role — viewing, editing, and administrative actions each require the appropriate membership level.

No sale of uploaded masters

TrackLock does not sell, license, or otherwise distribute your uploaded audio to third parties. Audio is used only to generate fingerprints and check matches.

How matching works

Uploaded audio is compared against registered assets using audio fingerprinting, not manual listening. A match produces a confidence score, not an automatic legal conclusion.

Limitations

No fingerprinting system detects every possible transformation, and no automated decision replaces human judgment in a dispute. See our Product Limitations page for specifics.

TrackLock does not currently hold SOC 2, ISO 27001, or other third-party security certifications.