Trust & security

How we handle your brand,
your persona, your data.

The honest version of what every legal, security, and brand team asks before signing. SOC 2 posture, DPA, SSO, IP terms, FTC AI disclosure, regulated-category handling. If a question below isn't answered, ask us on the demo call and we will write the answer here too.

The four promises

What you can count on, written plainly.

Your brand is yours

Every asset you give us (logos, voice samples, product footage, brand guidelines) is held under your account. You can export everything and delete on request, with no retention beyond what is needed to keep your account operational.

Your persona is yours

The AI persona built for your brand is exclusive to you. We do not reuse the face, voice, or hook bank with any other brand. If you cancel, the persona retires it is not licensed to a successor account.

You see it before it ships

Every reel passes a 4-axis quality gate before publish. Approval-before-publish can be turned on at any time, so nothing lands on your feed without you reviewing it first.

We are private-beta honest

We are at private-beta scale, not Fortune-500 scale. The list below is what we have today and what is in progress not what we wish we had.

At a glance

What we have today, in progress, and on the roadmap.

Today

  • DPA (GDPR + CCPA)
  • Encryption at rest + in transit
  • EU data residency (default)
  • 2FA on publish seats
  • Manual quality gate (4-axis)
  • Hard-delete on cancellation
  • FTC AI-disclosure labels

In progress

  • SOC 2 Type II audit (2026)
  • SAML SSO (Okta, Azure, Google)
  • Custom MSA on Agency annual
  • US data residency pin
  • Approval-before-publish toggle

On the roadmap

  • SCIM provisioning
  • APAC data residency
  • ISO 27001
  • HIPAA-aligned workspace
  • Custom retention schedules

Detailed answers

The full version of every question above.

Click through each. If your security or legal team needs something we don't cover here, write it in the demo booking notes and we'll bring a documented answer to the call.

What is your security posture? SOC 2?

SOC 2 Type II is on the 2026 roadmap, scoped to start mid-year once private-beta volume justifies the audit. Today we run on Vercel (Frankfurt + Washington edges) and Supabase (eu-west-1 primary), both SOC 2 Type II attested upstream. Internal practices: encryption at rest and in transit, least-privilege admin access, key rotation, no developer access to customer brand data without an explicit approved support ticket. We can share a one-pager covering today's posture on the demo call.

Do you offer a DPA and MSA?

Yes. Our standard DPA covers GDPR and CCPA processor obligations and is available on every paid tier. An MSA with mutual indemnification, custom payment terms, and SLA language is available on the Agency annual and Enterprise tiers. Both documents can be sent during demo follow-up no separate procurement portal step required.

Where is my data stored? Data residency options?

Customer account data, brand assets, and rendered reels are stored in eu-west-1 (Ireland) by default. US-only and APAC residency is available on the Enterprise tier with a workspace-level region pin. We do not ship customer data outside the pinned region except for read-only delivery to social platforms (Instagram, YouTube, etc.) when publishing the reels you ask us to publish.

Do you support SSO?

SAML SSO via Okta, Azure AD, Google Workspace, and JumpCloud is available on Agency annual and Enterprise. SCIM provisioning available on Enterprise. Standard email-link sign-in is the default on Brand and Studio tiers, with 2FA enforced for any seat with publish permissions.

Who owns the AI avatar (persona) we build for our brand?

You do. The persona output (face, voice, hook bank, rendered reels) is licensed to your brand exclusively for as long as your account is active. If you cancel, the persona is retired and not reissued to any other brand. The underlying generative models are upstream third-party (e.g., voice cloning, video generation providers); their terms are passed through transparently and listed in your account on request. We never train models on your brand's content.

How do you handle FTC AI-disclosure requirements?

Every reel we ship can include an in-frame AI-generated label and an in-caption disclosure tag both on by default for the Brand tier and configurable on Studio and above per platform and per persona. We follow current FTC guidance on AI-generated likeness in advertising contexts. For paid promotion or affiliate disclosures, your account-level disclosure copy is appended automatically to the caption.

Do you work with regulated categories health, finance, supplements?

Yes, with category-specific guardrails. Health and supplements use a claim-checking layer that strips unsubstantiated health claims and substitutes structure-function language where appropriate. Financial services and personal finance use FINRA/SEC-aware copy guardrails. We do not currently work with pharma DTC, regulated medical devices, or licensed financial advice products those have category-specific requirements that exceed what we can underwrite at private-beta scale.

Can my legal or security team review your systems before signing?

Yes. On Agency annual and Enterprise we run security questionnaires (CAIQ, VSA, custom) and answer follow-ups directly. Typical turnaround is 5-7 business days from questionnaire receipt. A vendor security review call with our team is part of the Enterprise demo flow.

What happens to my data if I cancel?

On cancellation, your account moves to a 30-day grace window during which you can re-activate, export all assets and rendered reels, or trigger immediate deletion. After 30 days, the account is hard-deleted: brand assets, persona artifacts, rendered reels, and analytics history are removed from primary storage. Backups roll off on a 90-day cycle. We can provide a deletion-confirmation letter on request.

How do you handle a brand-safety incident? If a reel ships that shouldn't have?

Our quality gate catches the vast majority of brand-safety issues before publish, but if something does ship that you flag as off-brand or non-compliant: you (or any seat with publish permissions) can hit Unpublish in the dashboard and the reel is taken down across all platforms within 5 minutes via the platform APIs. We then run a root-cause review and update the persona's guardrails so the same shape of issue cannot recur.

Need a security questionnaire,
DPA, or MSA?

Book a demo and add a note about what your team needs. We answer security and procurement questions within 5-7 business days, often the same week.