Controls you can check, and straight answers
Signed exports, roles enforced on the server, scoped keys and EU storage, each described as it is built. Then the things we do not have yet, stated before you have to ask.
What we do
Described as built. Not independently attested.
Access and identity
Sign-in
LiveEmail and password, or Google. One account per person across the editor, dashboard and developer portal.
Roles inside a team
LiveOwner, admin, member and viewer, ordered. Every permission is re-checked on the server on every request; the interface only decides what you are shown. A non-member gets a 404, not a 403, so organisation ids cannot be enumerated.
Invites
LiveBound to the invited email and expire after seven days. An invite grants admin at most; ownership is a transfer. Re-inviting replaces the old token.
SSO with SAML or OIDC
Not yetNot implemented. You cannot federate sign-in to Okta, Entra ID or Google Workspace as an identity provider.
SCIM deprovisioning
Not yetRemoving someone is a manual action by an owner or admin. Nothing syncs from your directory.
Enforced MFA
Not yetWe cannot require it. If people sign in with Google, your Google policy applies, but Vidmoat neither sets nor checks it.
Credentials and API
Scoped API keys
LiveEach key carries only the scopes you give it, from 18 coarse permissions such as projects.write and ai.agent. Keys are stored as hashes and shown once.
Scopes cannot escalate
LivePassing the scope check never skips the plan or credit check, so a scope cannot buy a feature the plan does not include.
OAuth apps with a consent screen
LiveFor products acting on your users’ behalf. The consent screen and the key form are generated from one description of each permission.
Rate limiting
LiveA sliding-window limiter in front of every metered service. On Enterprise your agreement sets the requests a minute for your members’ API keys (600 by default). Expensive work fails closed when the limiter cannot be reached.
Signed webhooks
LiveHMAC-SHA256 over a timestamp and the raw body, so your receiver can refuse forgeries and replays.
Customer-visible audit log
Not yetWe keep internal event and admin activity logs, but there is no view or export of your own organisation’s audit trail yet.
Data handling and deletion
Encrypted secrets
LivePlatform tokens, connected provider keys and stored automation credentials are encrypted with AES-256-GCM, and storage fails closed if the key is missing.
Account deletion removes the files
LiveDeleting an account deletes its rows and its files, not just the references. Unreferenced uploads are deleted after 72 hours.
Asset ledger
LiveEvery upload has a row: who, when, size and a SHA-256 of the contents. Re-uploading the same file reuses it.
Team-scoped media
LiveAn asset can move into a team library, which changes who can see it. On a paid plan the library is carried by the organisation’s pooled storage, and members’ own files count against their own plan first.
Customer-managed keys
Not yetStorage is encrypted at rest by the host. You cannot supply or rotate your own key.
Choice of region
Not yetFiles are stored in the EU, and that is the only option. You cannot pin data to another jurisdiction.
Application and infrastructure
Transport and browser hardening
LiveHSTS for two years with subdomains and preload, nosniff, a strict referrer policy, cross-origin opener isolation and framing denied.
Content Security Policy
Report-onlyA CSP ships in report-only mode. Enforcing it needs per-request nonces first, and a guessed policy in enforcement mode takes the site down.
Safe deploys
LiveReleases build into an inactive slot, so a deploy never pulls files out from under live requests. The process carries crash guards.
High availability
Not yetOne application server. No failover and no contractual uptime.
Offsite backups
Not yetThe database is backed up on the same machine. Offsite replication is not in place yet.
Status page
Not yetA health endpoint the platform monitors itself with, but no public status page or formal incident notices.
Provenance
Signed exports
LiveEvery render is tagged VM1-<job>-<timestamp>-<signature> with HMAC-SHA256, and anyone can check it at vidmoat.com/verify.
Proves origin, not pixels
LimitThe signature covers the render job and its time, not a hash of the frames, so it cannot prove nothing was edited afterwards.
Survives a platform re-encode
Not yetContainer metadata is stripped when TikTok or YouTube re-encode a file. Verify the master you hold.
Forensic watermark
Off by defaultWritten and disabled, because the first version left a faint visible artefact. Do not plan around it.
What we do not have yet
“Not yet” means nothing is underway. “On request” means a person arranges it.
SOC 2 or ISO 27001
Not yetNo audit has been performed and none is underway, so we will not call it "in progress".
Third-party penetration test
Not yetNone commissioned, so there is no report to share.
SSO, SAML or SCIM
Not yetSign-in is email or Google, per person. No federation, no automated deprovisioning.
High availability and an uptime SLA
Not yetOne application server. No failover and no contractual uptime figure.
Forensic watermark
Off by defaultBuilt and switched off: the first version left a visible artefact.
Contracts, DPA and invoicing
On requestNot self-serve. A person works through them with you.
Security questionnaire
On requestWe fill yours in, and the answers match this page, including the rows that say no.
Where your data lives
In plain words, from our privacy policy and subprocessor list.
Stored in the EU
Account records and media are on our server in Helsinki, Finland, mirrored to object storage in Stockholm, Sweden. Exports are stored alongside them. Privacy, section 5
AI processing goes abroad
To answer an instruction we send text, and sometimes sampled video frames, to AI providers in the United States, Singapore and China. Every one is named, with what it receives. AI providers
Not used to train models
We do not use your videos, audio, images, transcripts or projects to train generative AI models, and do not let providers do so with what we send them. Privacy, section 3
One adjacent thing, stated plainly
When an agent run succeeds we may keep the sequence of editing commands it produced, with its instruction, to plan better next time. Never your media. Ask and we exclude your runs. How it works
Some work never leaves the browser
Visual labelling and silence detection run on your own machine. Transcription runs on our servers or in your browser, not at a third party. Privacy, section 4
Retention you can read
Your work stays until you delete it. Unreferenced uploads go after 72 hours, deleted media leaves the backup store within 30 days, API request logs after 30 days. Retention table
Who processes data for us
| Group | Companies | Where |
|---|---|---|
| Infrastructure | Hetzner, Amazon Web Services, Vercel, Google Firebase Authentication | Finland, Sweden, United States |
| AI model providers | OpenAI, Alibaba Cloud (Qwen), DeepSeek, xAI, Google (Gemini) | United States, Singapore, China |
| Payments, email and operations | Dodo Payments, Paystack, Customer.io, Sentry and others | United States, EU and others |
| Only if you use them | Social platforms you publish to, chat apps, stock libraries, plugins you install | Various |
What we can send you
Only documents that exist or that we can produce.
Data processing agreement
On requestAsk and we work through one with you. Not a click-through, and we will say what we cannot commit to.
Completed security questionnaire
On requestSend yours. The answers will match this page.
Company registration
AvailableBuzz Innovations Ltd, company 17212684, on the public register at Companies House.
Invoices with bank details
On requestNumbered invoices with payment details and your PO reference, for annual Enterprise terms.
Subprocessor list
AvailableEvery company that processes customer data, by name, with what it receives and where.
SOC 2 report or pen test report
Not yetNeither exists, so neither can be shared.
Report a vulnerability
Use the contact form, or email support@s-ticketing.vidmoat.com with “security” in the subject. Both open a ticket that a person reads, usually the same day.
Say what you found and how to reproduce it, and give us a chance to fix it before you publish. There is no bug bounty programme yet.
Changes to this page
Trust page rebuilt: controls grouped, a status grid for what we do not have, documents on request, where your data lives, and this changelog.
Is an empty row blocking you?
Tell us which one, and we will say honestly whether it is weeks or quarters.