Security

A secure AI video platform, built to pass procurement.

AES-256 at rest, TLS 1.2+ in transit, GDPR self-serve deletion, and SOC 2 Type I targeted Q3 2026. MFA, audit logs, tenant isolation, rate limiting, geo-blocking, and a hardened upload path — already running production workloads.

Account security

Defense in depth on every login

Strong auth, session hygiene, and brute-force protection.

Multi-factor auth

TOTP authenticator apps. Optional enforcement at workspace level.

SSO

Native SSO; SAML and OIDC for Enterprise via standard connectors.

Rate limiting

Per-account and per-IP throttles on login, API, and signup endpoints.

Data protection

Yours stays yours

Tenant isolation, encrypted secrets, and GDPR-compliant deletion paths.

Tenant isolation

Your workspace is walled off by design — no one outside it can read your data.

Encrypted at rest

AES-256 encryption on stored files. Secrets stored write-only — never echoed to the browser.

Encrypted in transit

TLS 1.2+ on all external endpoints. HSTS preload-ready.

GDPR deletion

Self-serve account deletion. Hard-delete pass within 30 days, audit-logged.

Geo-blocking

Region allow/deny lists at the workspace level for residency compliance.

Data isolation

Every workspace's files are kept separate, so your media is never mixed with anyone else's.

Hardened uploads

Nothing untrusted lands without validation

MIME sniffing, magic-byte checks, size limits, and CSP-scoped delivery.

MIME validation

Server checks magic bytes — the extension lie does not pass.

CSP & CORS

A strict content-security policy and locked-down cross-origin rules on every page.

Quota walls

Per-plan file size and request caps. 413/429 with clear remediation.

Audit & observability

Every meaningful action, logged

Mail thread on records + structured audit table for high-volume events.

Per-record audit

Edits, approvals, renders, publishes — actor + timestamp on every model.

Spend tracking

Every AI charge is recorded and can't be altered, so anomalies surface before they reach your invoice.

AI assistant access

A credential that can spend money is treated like one

Connecting an assistant through the MCP integration issues a scoped API key. Everything about its life is deliberately short and narrow.

Bound at creation

Each key acts on your personal account or one specific agency — chosen when it is made, immutable afterwards. No argument widens the scope and no call can switch context.

30 days maximum

Keys expire, with reminder emails a week and a day before. Rotation issues a replacement immediately and keeps the old one alive briefly, so short lifetimes cost no downtime.

Idle keys are revoked

A key unused for a fortnight is withdrawn after a warning. Any authenticated request resets the clock, so only forgotten credentials are caught.

Shown once, never retrievable

A key is displayed at creation and never again. Nothing in the platform can recover it — lost keys are revoked and replaced, not looked up.

Spend ceilings and pacing

Set credits per day, week or month on a key; a start that would breach the ceiling is refused before any money moves. One production runs at a time per key.

A gate an agent cannot pass

Starting requires a live price quote, storyboard approval requires a person, and no tool publishes anywhere. Automation stops short of every irreversible step.

Voice cloning policy

Custom voices require consent

A custom voice ID may only be created and used with the voice owner's explicit permission.

A voice may only be cloned or used with the explicit, documented consent of the voice owner. You are responsible for holding that consent before uploading or generating a custom voice.

Prohibited use

Impersonation, fraud, and any deceptive or non-consensual use of a cloned voice are not permitted. The same applies to voices created without the owner's consent.

Compliance posture

Where we stand

GDPR-aligned today; SOC 2 in progress.

GDPR

DPA available on request. EU data residency option on Enterprise.

CCPA

Self-serve data export and deletion meet "right to know" + "right to delete".

SOC 2

Type I targeted Q3 2026. Type II following 12-month observation period.

Security & compliance — procurement questions

Is StudioCut.Video GDPR compliant?

Yes. StudioCut.Video is GDPR-aligned with self-serve data export and deletion. Personal data is deletable on request through the account settings, and the same wording applies across our privacy policy.

Are you SOC 2 certified?

SOC 2 Type I is targeted for Q3 2026, with Type II following a 12-month observation period. We can share our current security posture and controls during procurement.

How is my data encrypted?

Data is encrypted with AES-256 at rest and TLS 1.2+ in transit. Secrets are stored write-only and never echoed back to the browser.

How are tenants isolated?

Each account's data is walled off from every other, backed by an immutable audit log so every action is traceable.

Report a vulnerability

Found something? Email security@studiocut.video. PGP key on request. We respond within one business day and credit disclosures with permission.