Trust, Security & Accessibility
How VTA protects your data, stays transparent about its limits, and keeps the platform usable for everyone.
Data Security
VTA takes a privacy-first approach to data handling. Ad content submitted for audit is stored only for the purpose of generating your compliance report and is associated with the email you provide. We do not sell, share, or rent your data to third parties. All data in transit is encrypted via HTTPS/TLS, and data at rest is stored in a managed database with role-based access controls. File uploads use private storage with signed URLs, so only authorized users can access them. You can request deletion of your audit records at any time from the Profile page, and we will remove them from our active database.
Transparency
VTA is an AI-powered compliance auditor — not a law firm and not a substitute for legal counsel. Every audit result includes the regulatory rules it was checked against, the legal citations retrieved from public government databases (Cornell LII, Federal Register, EUR-Lex), and a SHA-256 cryptographic seal that proves the audit was run at a specific time with a specific model version. We disclose the LLM model used for each scan, the jurisdiction selected, and any limitations of the keyword, RAG, and likeness detection layers. When the audit engine cannot verify a claim, it says so — it does not fabricate citations or pass unknown content as compliant. This transparency is core to how VTA works and is embedded in every report we generate.
Accessibility Statement
VTA is committed to making its compliance auditing platform accessible to all users, including those with disabilities. We follow WCAG 2.1 Level AA guidelines where feasible: our interface uses semantic HTML, keyboard-navigable components, sufficient color contrast, and descriptive labels for interactive elements. All forms, buttons, and navigation can be operated without a mouse. We are actively working to improve screen reader compatibility, add ARIA landmarks to dynamic content, and ensure our PDF reports are readable by assistive technology. If you encounter an accessibility barrier while using VTA, please contact us at vta@nicolasurrutia.com and we will work to resolve it promptly.
Regulatory Posture
VTA itself is designed with compliance in mind. We are aware of the EU AI Act Article 52 transparency requirements and the NO FAKES Act's restrictions on unauthorized likeness use. Our audit engine checks user content against these frameworks, and our own practices align with them: we disclose AI usage, we do not generate deepfakes or synthetic likenesses, and we maintain an audit trail of how content was processed. VTA does not provide legal advice and does not create an attorney-client relationship. Any compliance score or certificate generated by the platform is a decision-support output, not a binding legal opinion.
Encryption
TLS in transit, encrypted storage at rest, signed URLs for private files.
Data Retention
Audit records kept until you delete them. No third-party data sharing.
Audit Trail
SHA-256 sealed reports with model version, timestamp, and citations.
WCAG 2.1 AA
Keyboard navigation, semantic HTML, contrast, and ARIA labels.