Features
White Label
Pricing About
Resources

The InterSpace Group

Trust Center

Security built into the infrastructure.

ToneGrid runs distribution businesses under other companies' names. That means your catalog, your artists' data, and your DSP relationships sit on our infrastructure. This page explains how we protect them, what we commit to, and what we do not claim.

TLS 1.2+

Every connection, with HSTS enforced

99.9%

Uptime target, tracked on our status page

July 2026

Independent penetration test, findings remediated

MFA

Available for every account, enforceable per tenant

Platform Security

Protected at every layer

The controls below apply to every tenant on the platform, on every plan, from the first day.

Encryption in transit

All ToneGrid hosts accept TLS 1.2 and 1.3 only. HTTP Strict Transport Security is enforced, and every host ships a strict Content Security Policy together with the standard hardening headers: frame protection, content-type sniffing protection, referrer policy, and a restrictive permissions policy.

Authentication

Accounts can enable multi-factor authentication with an authenticator app (TOTP) or email codes, and a tenant can require it for every admin. Login endpoints are rate-limited to stop credential stuffing. Session cookies are Secure, HttpOnly, and SameSite, set at the server level so no application code can weaken them.

Access control

Tenant admins get role-based permissions, so a QC reviewer cannot touch billing and a label manager cannot change DSP routing. ToneGrid's own super-admin layer is separate from tenant administration. When a ToneGrid staff member acts inside a tenant account, the action is attributed to that staff member, never to the client.

Audit trail

Every tenant-admin action is written to an audit log with the actor, the endpoint, the target record, and the originating IP address. Field-level edits to releases and tracks record the before and after values. Each user also has a complete activity history, so questions like "who changed this split" have an answer.

API security

The API uses bearer API keys issued per integration. A key inherits the role of the user who owns it, never more. Keys can be rotated or revoked at any time from the dashboard, all requests are TLS only, and every tenant has its own rate limit. The full reference is at api-docs.tonegrid.pro.

Secure delivery

Releases are delivered to DSPs as DDEX ERN 4.3 over authenticated channels agreed with each store. Each delivery produces a receipt, and every delivery event is written to the audit log, so you can show an artist exactly when a release left the platform and when the store acknowledged it.

Compliance and Privacy

What we commit to, in writing

GDPR

ToneGrid processes personal data about your artists and team on your behalf. We honor data subject requests for access, correction, and deletion, and we help you respond to requests you receive. A Data Processing Agreement is available on request for every paid plan. Write to hello@tonegrid.pro to request one, or to raise a data subject request.

SOC 2 and ISO 27001

Our control set is mapped to the SOC 2 Trust Services Criteria and ISO 27001 Annex A. We share the control mapping with Enterprise customers under NDA. ToneGrid does not currently hold a SOC 2 report or ISO 27001 certificate, and we will update this page when that changes.

Data residency

Standard plans run on our primary infrastructure in the United States. Enterprise plans can pin tenant data to a specific region. If your artists or your regulator need data to stay in a particular jurisdiction, tell us during onboarding and we will scope it into your agreement.

Subprocessors

These are the third parties that may process customer data on ToneGrid's behalf. We will update this list before adding a new subprocessor.

Subprocessor Purpose Location
Amazon Web ServicesHosting, object storage, email delivery via SESUnited States
CloudinaryImage processingUnited States
PaystackBillingNigeria
ACRCloudAudio fingerprinting and AI music detectionGlobal
GoogleAnalytics and fonts on the public website onlyUnited States

Vulnerability disclosure

If you find a security issue in any ToneGrid property, tell us at hello@tonegrid.pro. Our contact details are also published at /.well-known/security.txt.

We acknowledge reports within 2 business days, keep you informed while we fix the issue, and will not pursue legal action against researchers who act in good faith and avoid accessing other people's data.

Incident response

Security events are triaged by the engineering team, contained first, then investigated. We keep a written record of every incident and the remediation that followed.

If we confirm a breach involving personal data, we notify affected customers without undue delay and within 72 hours, with what happened, what data was involved, and what we are doing about it.

Business continuity

We target 99.9% availability for the platform and the API, and we publish live and historical availability on status.tonegrid.pro, where you can subscribe to incident updates.

Enterprise plans include a contractual SLA with service credits, a named point of contact, and agreed maintenance windows.

Run your distribution on infrastructure you can audit.

Every plan ships with the controls on this page. Pick the one that fits your catalog, and ask us for the DPA or the control mapping whenever your team is ready.