Where your data lives
The Monitor and its database run on servers in the Netherlands, operated by Soundcheck Software Ltd. All traffic uses HTTPS.
Signing in
- A password of at least ten characters, stored only as a secure hash.
- A six-digit code by e-mail on every new device. You can trust a device for 30 days.
- Roles: owners manage people and billing, approvers sign off papers, members keep the ledger up to date.
- Repeated wrong attempts are slowed down and blocked.
Checked accounts
Every sign-up confirms its e-mail with a code. We check names and phone numbers, refuse temporary inboxes, and check VAT or company numbers against public registers such as the EU VIES service and Companies House. Doubtful sign-ups are reviewed by a person before they open.
Activity trail
Every change to the ledger, from sorting a tool to approving a paper, is recorded with the person's name and the time. Entries cannot be edited or deleted, and can be included in an evidence file.
Evidence files
Each evidence file is a fixed snapshot with a check code and a SHA-256 fingerprint of its contents. Anyone who receives one can confirm it at https://monitor.soundchecksoftware.eu/verify.php.
Monitor Scan
Monitor Scan is a small program that looks for AI tools on a computer and its local network. It is built to be acceptable to a works council and a data protection officer.
- Only matches leave the computer. The program compares what it sees with the AI catalogue on the computer itself. It sends the names of AI tools found and where they were found, never the full list of apps, the other websites visited or the contents of any file.
- It asks first. Every result is shown on screen before anything is sent. IT can run it unattended with
--yesfor company-wide roll-outs. - Nothing is installed. The program runs, reports and is removed. It does not stay in the background, record keystrokes or take screenshots.
- You choose the scope. Browser history and DNS checks, the local network check and the model file search can each be switched off, and computer names can be hidden.
- A key that can only report. Each company's scan key can send results and read the catalogue. It cannot read the ledger, and the owner can replace it at any time.
- The network check is gentle. It asks machines on the computer's own subnet a single harmless question on the ports AI servers use, nothing more.
Tell staff before you scan; the Scan page has a ready-made notice. Where there is a works council, agree the scan with them first.
Use of AI
The risk tier is never decided by AI. It comes from a fixed rules catalogue that cites the article behind each rule. If your account switches on redrafting, the text of a paper is sent to Anthropic's Claude to improve the wording, and a named person approves the result.
What we store, and what we do not
- Stored: your account and company details, the tools on your ledger, your answers and decisions, papers, evidence files and the activity trail.
- Not stored: the card or bank statement files and network logs you upload. They are read for AI tool names and discarded.
- Payments are handled by our payment provider. We never see or store card details.
- No advertising trackers on the website.
Contact
Questions about security or data protection: need@soundchecksoftware.eu. Read the privacy notice.