Access control
Workspace actions are tied to an organization and a role. Cross-site request checks apply to dashboard mutations.
Trust
Consent Guru protects workspace access, signs webhook deliveries, and keeps consent evidence separate from a rewritten current choice.
A consent log that an anonymous client can edit, or that disappears when a person withdraws, is not evidence. The product separates the current choice from historical snapshots and limits who can change configuration.
The controls below are the ones implemented in this application. They are not a certification, and they are not a promise about every customer’s own hosting environment.
Step 1
Dashboard access uses Clerk. Organization members have roles. Unauthenticated API calls to private routes are rejected.
Step 2
API keys are for machine access. Site keys are for the browser SDK on a verified domain. Webhook secrets sign outbound events.
Step 3
Audit logs capture configuration and access changes. Consent evidence snapshots keep the decision context.
Step 4
Retention windows cover consent evidence, consent records, audit events, and rights requests. Legal holds block automated deletion.
Workspace actions are tied to an organization and a role. Cross-site request checks apply to dashboard mutations.
Stored webhook signing secrets are encrypted with AES-256-GCM. Deliveries are signed with HMAC SHA-256.
Notice snapshots can be hashed with SHA-256 and decisions can be signed with HMAC so a receipt can be checked later.
Responses include baseline security headers. Production traffic sends HSTS. The product does not claim a third-party penetration-test report on this page.
Show the snapshot and the audit log entry instead of a screenshot of a banner.
Rotate API keys and webhook secrets without republishing the public banner.
Pause automated cleanup when a matter requires the record to stay.
Customer websites that install the SDK remain responsible for their own transport security, tag configuration, and who they grant workspace roles to.
These controls do not include a public SOC or ISO certificate on this page. Logos elsewhere on the marketing site should not be read as a certification of every control.
Webhook signing secrets are encrypted with AES-256-GCM. Consent decisions are stored as workspace data with access control, hashing of notice snapshots, and HMAC signatures on receipts. This page does not claim that every database column uses application-level encryption.
People with access to the organization workspace, subject to roles. Private dashboard routes are not indexed and require authentication.
Retention is configurable per category. Changing the setting does not rewrite historical evidence. Automated deletion skips records under a legal hold.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.