Security

Detection results live in sensitive processes

Because a result can affect a grade, a job or a public record, TraceMark AI treats access, retention and traceability as core product surfaces rather than settings buried in an admin panel.

Account security

Strong password policy, leaked-password checking, session management and two-factor enrolment.

Organization permissions

Five distinct roles with non-overlapping powers, enforced on every action.

Data retention

Choose how long originals, extracted text and derived evidence are stored.

Audit logging

Immutable record of submissions, status changes, exports and key usage.

Role permissions

RoleCan
OwnerFull access, billing, delete organization
AdministratorManage members, API keys, retention settings
ReviewerRun scans, set case status, write internal notes
MemberRun scans, view own results
Read-only/AuditorView scans, reports and audit logs only

Audit log — example entries

  • Created scan SC-48212026-09-20 14:33

    j.darwish · 203.0.113.24

  • Set case status → Needs Investigation (SC-4820)2026-09-20 11:20

    k.ali · 203.0.113.9

  • Added reviewer note (SC-4819)2026-09-19 18:02

    m.okafor · 198.51.100.77

  • Retention policy applied — 3 files purged2026-09-19 08:11

    system ·

  • Exported audit log (CSV)2026-09-18 16:45

    audit · 198.51.100.12

Responsible use

Our position on how results should be used

AI detection is probabilistic. This result does not establish authorship and should not be used as the sole basis for academic, employment, disciplinary, or legal decisions.