Multi-factor auth
TOTP authenticator apps. Optional enforcement at workspace level.
AES-256 at rest, TLS 1.2+ in transit, GDPR self-serve deletion, and SOC 2 Type I targeted Q3 2026. MFA, audit logs, tenant isolation, rate limiting, geo-blocking, and a hardened upload path — already running production workloads.
Strong auth, session hygiene, and brute-force protection.
TOTP authenticator apps. Optional enforcement at workspace level.
Native SSO; SAML and OIDC for Enterprise via standard connectors.
Per-account and per-IP throttles on login, API, and signup endpoints.
Tenant isolation, encrypted secrets, and GDPR-compliant deletion paths.
Your workspace is walled off by design — no one outside it can read your data.
AES-256 encryption on stored files. Secrets stored write-only — never echoed to the browser.
TLS 1.2+ on all external endpoints. HSTS preload-ready.
Self-serve account deletion. Hard-delete pass within 30 days, audit-logged.
Region allow/deny lists at the workspace level for residency compliance.
Every workspace's files are kept separate, so your media is never mixed with anyone else's.
MIME sniffing, magic-byte checks, size limits, and CSP-scoped delivery.
Server checks magic bytes — the extension lie does not pass.
A strict content-security policy and locked-down cross-origin rules on every page.
Per-plan file size and request caps. 413/429 with clear remediation.
Mail thread on records + structured audit table for high-volume events.
Edits, approvals, renders, publishes — actor + timestamp on every model.
Every AI charge is recorded and can't be altered, so anomalies surface before they reach your invoice.
Connecting an assistant through the MCP integration issues a scoped API key. Everything about its life is deliberately short and narrow.
Each key acts on your personal account or one specific agency — chosen when it is made, immutable afterwards. No argument widens the scope and no call can switch context.
Keys expire, with reminder emails a week and a day before. Rotation issues a replacement immediately and keeps the old one alive briefly, so short lifetimes cost no downtime.
A key unused for a fortnight is withdrawn after a warning. Any authenticated request resets the clock, so only forgotten credentials are caught.
A key is displayed at creation and never again. Nothing in the platform can recover it — lost keys are revoked and replaced, not looked up.
Set credits per day, week or month on a key; a start that would breach the ceiling is refused before any money moves. One production runs at a time per key.
Starting requires a live price quote, storyboard approval requires a person, and no tool publishes anywhere. Automation stops short of every irreversible step.
A custom voice ID may only be created and used with the voice owner's explicit permission.
A voice may only be cloned or used with the explicit, documented consent of the voice owner. You are responsible for holding that consent before uploading or generating a custom voice.
Impersonation, fraud, and any deceptive or non-consensual use of a cloned voice are not permitted. The same applies to voices created without the owner's consent.
We may suspend accounts for voice-cloning misuse. Report a suspected violation to security@studiocut.video.
GDPR-aligned today; SOC 2 in progress.
DPA available on request. EU data residency option on Enterprise.
Self-serve data export and deletion meet "right to know" + "right to delete".
Type I targeted Q3 2026. Type II following 12-month observation period.
Yes. StudioCut.Video is GDPR-aligned with self-serve data export and deletion. Personal data is deletable on request through the account settings, and the same wording applies across our privacy policy.
SOC 2 Type I is targeted for Q3 2026, with Type II following a 12-month observation period. We can share our current security posture and controls during procurement.
Data is encrypted with AES-256 at rest and TLS 1.2+ in transit. Secrets are stored write-only and never echoed back to the browser.
Each account's data is walled off from every other, backed by an immutable audit log so every action is traceable.
Found something? Email security@studiocut.video. PGP key on request. We respond within one business day and credit disclosures with permission.