Security
How we protect your accounts, your credentials, and your money's paper trail
You are handing us the keys to your royalty accounts. That is not a small thing, and we built RoyaltyCoPilot as if it were our own catalog on the line. Here is exactly how we handle your access, your credentials, and your money's paper trail, in plain language.
How we connect to your accounts
We never sneak into your accounts, and we never pretend to be you.
When you connect a rights organization like The MLC, you choose one of two ways in:
- You approve an invite. We use the rights organization's own invite system to add a clearly labeled user named "RoyaltyCoPilot" to your account. You send the invite, you can see the user in your account settings, and you can remove it yourself at any time.
- You share credentials. If you give us a login instead, we use it only to do the work you asked for, and we protect it the way we describe below.
Our delegated user gets the smallest set of permissions that can do the job. At The MLC, that means the Finance and Copyright roles only. Never Super User. The delegated user has its own email address on a domain we control and its own multi-factor authentication, so it is never a shadow copy of your login.
How your credentials are protected
- Every stored credential is encrypted with AWS KMS envelope encryption. In practice that means each credential gets its own encryption key, and that key is itself locked by a master key we never see in plaintext.
- Credentials are encrypted at rest and in transit, always.
- When you disconnect an account, an automated cleanup service scrubs your credentials immediately, and any residual encrypted copies are deleted within 30 days.
Every action is deliberate and on the record
- You approve every claim. A claim is a legal statement that you own something. RoyaltyCoPilot prepares claims, but nothing is filed until you approve that specific claim. There is no bulk auto-file, ever.
- Dry runs. Where supported, you can preview exactly what a filing will do before it happens.
- Kill switch. An emergency stop halts all automated activity instantly if anything ever looks wrong.
- Receipts for everything. We capture screenshots and evidence for every action taken on your accounts, so you can verify what we did, not just take our word for it.
- Locked-down plumbing. Every API request to our backend is cryptographically signed, every data access is scoped to your user, and everything is audit-logged. Our infrastructure runs on AWS (us-east-1).
What we will never do
- Never file a claim without your approval of that specific claim.
- Never hide our identity on your account. Our access is always a named, visible "RoyaltyCoPilot" user or an authorization you granted.
- Never sell your data. Your catalog, splits, and statements are not a product.
- Never touch your writer's share. Performance royalties your PRO pays directly to you as a writer keep flowing straight to you, unless you explicitly ask us in writing to handle them.
If something ever goes wrong
If we confirm a security breach that affects your data, you will hear it from us first. We will email you without undue delay, and in any event within 72 hours of confirming the breach, and we will tell you three things straight: what happened, what data was involved, and what we are doing about it. No burying it in a blog post six months later.
How to disconnect, and what happens when you do
Leaving is safe, and it is designed to be. Disconnect any rights organization (or close your account) and our exit protocol runs:
- Within 7 days, we remove our delegated user from your rights organization account.
- Within 30 days, we delete your stored credentials, including backups.
- We email you to confirm both steps are done.
Everything we registered or claimed for you stays in place and stays yours. Your registrations live at the rights organization, not inside RoyaltyCoPilot, so nothing breaks when you go.
Found a vulnerability?
We want to hear about it. Email security@royaltycopilot.ai and we will respond quickly, work with you on a fix, and credit you if you want credit. Please give us a reasonable window to patch before public disclosure.
Where we are headed
We are building toward SOC 2 readiness and will publish updates here as that work progresses. We do not claim SOC 2 certification today, and we will not claim it until an independent auditor says so.
Questions about any of this? Email security@royaltycopilot.ai. A human who works on this system will answer.