Chat on WhatsApp

Trust

Security controls for consent evidence

Consent Guru protects workspace access, signs webhook deliveries, and keeps consent evidence separate from a rewritten current choice.

Consent evidence is only useful if it is hard to quietly change

A consent log that an anonymous client can edit, or that disappears when a person withdraws, is not evidence. The product separates the current choice from historical snapshots and limits who can change configuration.

The controls below are the ones implemented in this application. They are not a certification, and they are not a promise about every customer’s own hosting environment.

Controls that exist in the product

  1. Step 1

    Authenticate

    Dashboard access uses Clerk. Organization members have roles. Unauthenticated API calls to private routes are rejected.

  2. Step 2

    Separate credentials

    API keys are for machine access. Site keys are for the browser SDK on a verified domain. Webhook secrets sign outbound events.

  3. Step 3

    Record changes

    Audit logs capture configuration and access changes. Consent evidence snapshots keep the decision context.

  4. Step 4

    Retain deliberately

    Retention windows cover consent evidence, consent records, audit events, and rights requests. Legal holds block automated deletion.

Key capabilities

Access control

Workspace actions are tied to an organization and a role. Cross-site request checks apply to dashboard mutations.

Encryption of webhook secrets

Stored webhook signing secrets are encrypted with AES-256-GCM. Deliveries are signed with HMAC SHA-256.

Consent proof

Notice snapshots can be hashed with SHA-256 and decisions can be signed with HMAC so a receipt can be checked later.

Transport and browser headers

Responses include baseline security headers. Production traffic sends HSTS. The product does not claim a third-party penetration-test report on this page.

What teams use it for

  • Historical evidence is not erased just because the current choice changed.
  • Webhook receivers can detect tampering.
  • Domain verification limits where a site key is accepted.
  • Retention is a setting you can explain, not an unbounded archive by accident.

Audit questions

Show the snapshot and the audit log entry instead of a screenshot of a banner.

Key handling

Rotate API keys and webhook secrets without republishing the public banner.

Legal holds

Pause automated cleanup when a matter requires the record to stay.

Privacy considerations

Customer websites that install the SDK remain responsible for their own transport security, tag configuration, and who they grant workspace roles to.

These controls do not include a public SOC or ISO certificate on this page. Logos elsewhere on the marketing site should not be read as a certification of every control.

Questions

1.Are consent records encrypted?

Webhook signing secrets are encrypted with AES-256-GCM. Consent decisions are stored as workspace data with access control, hashing of notice snapshots, and HMAC signatures on receipts. This page does not claim that every database column uses application-level encryption.

2.Who can see consent evidence?

People with access to the organization workspace, subject to roles. Private dashboard routes are not indexed and require authentication.

3.How long is evidence kept?

Retention is configurable per category. Changing the setting does not rewrite historical evidence. Automated deletion skips records under a legal hold.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.