Trust and Safety

How Textimony keeps your evidence private, sourced, and auditable.

Textimony handles sensitive message records inside authenticated cases and keeps source references, analysis output, reviewer decisions, and report files connected.

Traceable outputs

Reports are designed to retain message identifiers, timestamps, participant mappings, source-file references, and run manifests.

Current security posture

Live traffic is served over HTTPS through Cloudflare, app sessions are account scoped, and production sessions use secure HTTP-only cookies on the live domain.

Configured controls

The current server-side analysis app uses account-scoped workflows, HTTPS transport, secure cookies, and report artifacts.

Data flow

A signed-in user creates a case, uploads an export, confirms participants and time handling, imports the messages, starts analysis, reviews candidates tied to source rows, and downloads reports for that case run.

Authentication and tenant isolation

The app uses account sessions, ownership checks, and case-scoped routes so cases and reports remain inside the owning account workflow.

Retention, deletion, backups, and legal holds

The privacy policy explains retention and the deletion-request channel. Backups, abuse prevention, billing records, active disputes, security incidents, or legal holds can affect a request.

Model processing and training

Current analysis runs server side in the case workflow. Customer message content is not used to train public models or sold to data brokers.

Third-party processors and disclosure

Cloudflare supports public routing, Google OAuth supports sign-in, email providers support notifications, Microsoft Clarity and other analytics providers process public-site traffic events, and security reports route through security.txt.

Clearly labeled examples

Public sample messages and charts are labeled as illustrative and do not come from a real case.

Controls a user can inspect

The current product exposes account-scoped cases, HTTPS transport, secure session cookies, file fingerprints, report artifacts, run manifests, and public privacy and security contacts.

Product boundaries

Public pages distinguish software-generated candidates, reviewer decisions, and questions that require qualified legal counsel.