TRUST CENTER · CUSTOMER AUDIO

Clear answers for the people who review your vendors.

A practical summary of how Tonn handles audio and what is covered by enterprise agreements.

Last reviewed: September 2026 · For contractual terms, the signed agreement controls.

Download security summary ↓

01 / MODEL USE

No training on customer audio

Customer audio is not used for model training, fine-tuning, evaluation or benchmarking. The API Terms licence permits processing requests, debugging failures and maintaining service quality.

02 / AUDIO LIFECYCLE

Temporary processing

Source audio, intermediate files and previews are deleted from temporary storage after processing and are not kept long-term. Upload URLs expire after 1 hour; output URLs expire after 24 hours.

03 / LOCATION

EU processing

Audio processing and storage run on Google Cloud Platform in europe-west1, Belgium. GCP is the infrastructure subprocessor for audio storage and processing.

04 / CUSTOMER STORAGE

Use your own audio URLs

You can provide URLs to audio held in your own storage, provided they are reachable by the service. Contact us if your integration requires signed-URL validation.

05 / RIGHTS

You retain your rights

RoEx does not claim ownership of customer content or output. You may submit audio on behalf of your end users when you hold the necessary rights and submit requests under your account. Stem separation does not grant additional rights.

06 / DEPLOYMENT

Cloud API or licensed SDK

The C++ SDK can run on customer infrastructure under an annual licence. Ask RoEx to confirm the supported deployment platforms for your target environment.

ENTERPRISE AGREEMENTS

Terms for production partnerships.

Self-serve terms do not include a DPA, formal incident-notification commitment or contractual SLA. DPA, incident terms, SLAs and metadata retention/erasure terms are negotiated under an enterprise agreement with guaranteed monthly volume.

Request erasure of metadata and usage records via support@roexaudio.com. A public deletion timeframe has not been stated.

Not stated as a public commitment

  • Metadata and billing-log retention duration
  • Encryption specifics (beyond HTTPS transport and GCP defaults)
  • Security certifications such as SOC 2 or ISO 27001
  • Full subprocessors for billing, email and analytics

Ask for current answers before procurement review. We do not publish unconfirmed controls as commitments.

Ask a security question ↗

SECURITY REVIEW

Need a DPA or enterprise terms?

Tell us about your product, expected monthly volume and review requirements.

Contact RoEx ↗