ProdExplainerProdExplainer

Legal

Security

How we protect your account, your uploads and the videos you generate.

Last updated 19 August 2026

Encryption

  • All traffic is served over HTTPS with modern TLS; HTTP requests are redirected.
  • Uploads and rendered videos are stored on encrypted volumes.
  • Passwords are stored only as salted hashes and are never recoverable in plain text.

Access control

  • Email verification is required before an account becomes active.
  • Sign-in supports Google, Microsoft, GitHub and Apple, so you can inherit your identity provider's controls.
  • Projects are scoped to your organisation; roles determine who can create, approve and delete.
  • Internal access to production is limited to the engineers who need it, over key-based SSH, and is logged.

Infrastructure

  • Services run in isolated containers with least-privilege credentials.
  • Secrets are held in environment configuration, never in source control.
  • Dependencies are patched on a regular cycle and monitored for published vulnerabilities.
  • Backups run daily and are restore-tested.

Your content

Uploads and generated media are private to your organisation by default. Share links, where you create them, are unguessable and can be revoked. We do not use your content to train models.

Incident response

We monitor for errors and abnormal activity. If an incident affects your data we will contact you without undue delay with what happened, what we know, and what we are doing about it.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. Please give us a reasonable window to fix the issue before disclosing it publicly. We do not take legal action against researchers who act in good faith, stay within their own test data and avoid degrading the service for others.