// last updated July 23, 2026

Security

Report suspected vulnerabilities privately so we can investigate and protect users.


Security measures

  • Encryption in transit for the application and provider connections, with provider-managed encryption at rest for the production database, object storage, and backups.
  • Clerk authentication, application-layer account authorization, and account-scoped database references. Production secrets are kept in service configuration and scoped to the services that need them.
  • Private object storage with short-lived signed links when a user or selected processor needs a specific file.
  • Ephemeral agent sandboxes receive only the account-scoped workspace needed for the run. Customer files are synchronized back through authenticated Vidify routes rather than a shared filesystem.
  • Consent-gated PostHog analytics with masked replay and excluded request bodies, media, prompts, and customer copy. Sentry receives sanitized errors and traces without request bodies, headers, cookies, query strings, AI inputs or outputs, or session replay.
  • Structured operational logging, health checks, provider kill switches, dependency and build verification, incident-response procedures, and tested database backup/restore procedures.
  • Operational telemetry, optional analytics, and sanitized error monitoring are limited to 90 days; encrypted backups expire within 35 days. See the Privacy Policy for the complete retention schedule.

Our Subprocessor List describes the external services that may process customer data. Security controls are reviewed when a provider, deployment region, or material product capability changes.

Responsible disclosure

Email [email protected] with the affected URL or component, impact, reproduction steps, and supporting evidence. Do not include secrets or personal data you do not need to demonstrate the issue. Our machine-readable policy is at /.well-known/security.txt.

Safe-harbor expectations

Act in good faith, avoid privacy violations and service disruption, stop when you access data that is not yours, and give us reasonable time to remediate before public disclosure. Do not use denial of service, social engineering, physical attacks, automated high-volume scanning, or destructive testing. This is not a bug-bounty promise.

What happens next

We validate and prioritize reports based on risk and share material progress when possible. Our incident process assigns an incident commander, operations lead, communications lead, and privacy/legal lead; prioritizes containment and evidence preservation; and requires a documented closeout. Legal demands, abuse reports, and account support should use the contact paths on the Privacy and Trust pages instead.