Skip to content

Controls you can check, and straight answers

Signed exports, roles enforced on the server, scoped keys and EU storage, each described as it is built. Then the things we do not have yet, stated before you have to ask.

What we do

Described as built. Not independently attested.

Access and identity

  • Sign-in

    Live

    Email and password, or Google. One account per person across the editor, dashboard and developer portal.

  • Roles inside a team

    Live

    Owner, admin, member and viewer, ordered. Every permission is re-checked on the server on every request; the interface only decides what you are shown. A non-member gets a 404, not a 403, so organisation ids cannot be enumerated.

  • Invites

    Live

    Bound to the invited email and expire after seven days. An invite grants admin at most; ownership is a transfer. Re-inviting replaces the old token.

  • SSO with SAML or OIDC

    Not yet

    Not implemented. You cannot federate sign-in to Okta, Entra ID or Google Workspace as an identity provider.

  • SCIM deprovisioning

    Not yet

    Removing someone is a manual action by an owner or admin. Nothing syncs from your directory.

  • Enforced MFA

    Not yet

    We cannot require it. If people sign in with Google, your Google policy applies, but Vidmoat neither sets nor checks it.

Credentials and API

  • Scoped API keys

    Live

    Each key carries only the scopes you give it, from 18 coarse permissions such as projects.write and ai.agent. Keys are stored as hashes and shown once.

  • Scopes cannot escalate

    Live

    Passing the scope check never skips the plan or credit check, so a scope cannot buy a feature the plan does not include.

  • OAuth apps with a consent screen

    Live

    For products acting on your users’ behalf. The consent screen and the key form are generated from one description of each permission.

  • Rate limiting

    Live

    A sliding-window limiter in front of every metered service. On Enterprise your agreement sets the requests a minute for your members’ API keys (600 by default). Expensive work fails closed when the limiter cannot be reached.

  • Signed webhooks

    Live

    HMAC-SHA256 over a timestamp and the raw body, so your receiver can refuse forgeries and replays.

  • Customer-visible audit log

    Not yet

    We keep internal event and admin activity logs, but there is no view or export of your own organisation’s audit trail yet.

Data handling and deletion

  • Encrypted secrets

    Live

    Platform tokens, connected provider keys and stored automation credentials are encrypted with AES-256-GCM, and storage fails closed if the key is missing.

  • Account deletion removes the files

    Live

    Deleting an account deletes its rows and its files, not just the references. Unreferenced uploads are deleted after 72 hours.

  • Asset ledger

    Live

    Every upload has a row: who, when, size and a SHA-256 of the contents. Re-uploading the same file reuses it.

  • Team-scoped media

    Live

    An asset can move into a team library, which changes who can see it. On a paid plan the library is carried by the organisation’s pooled storage, and members’ own files count against their own plan first.

  • Customer-managed keys

    Not yet

    Storage is encrypted at rest by the host. You cannot supply or rotate your own key.

  • Choice of region

    Not yet

    Files are stored in the EU, and that is the only option. You cannot pin data to another jurisdiction.

Application and infrastructure

  • Transport and browser hardening

    Live

    HSTS for two years with subdomains and preload, nosniff, a strict referrer policy, cross-origin opener isolation and framing denied.

  • Content Security Policy

    Report-only

    A CSP ships in report-only mode. Enforcing it needs per-request nonces first, and a guessed policy in enforcement mode takes the site down.

  • Safe deploys

    Live

    Releases build into an inactive slot, so a deploy never pulls files out from under live requests. The process carries crash guards.

  • High availability

    Not yet

    One application server. No failover and no contractual uptime.

  • Offsite backups

    Not yet

    The database is backed up on the same machine. Offsite replication is not in place yet.

  • Status page

    Not yet

    A health endpoint the platform monitors itself with, but no public status page or formal incident notices.

Provenance

  • Signed exports

    Live

    Every render is tagged VM1-<job>-<timestamp>-<signature> with HMAC-SHA256, and anyone can check it at vidmoat.com/verify.

  • Proves origin, not pixels

    Limit

    The signature covers the render job and its time, not a hash of the frames, so it cannot prove nothing was edited afterwards.

  • Survives a platform re-encode

    Not yet

    Container metadata is stripped when TikTok or YouTube re-encode a file. Verify the master you hold.

  • Forensic watermark

    Off by default

    Written and disabled, because the first version left a faint visible artefact. Do not plan around it.

What we do not have yet

“Not yet” means nothing is underway. “On request” means a person arranges it.

  • SOC 2 or ISO 27001

    Not yet

    No audit has been performed and none is underway, so we will not call it "in progress".

  • Third-party penetration test

    Not yet

    None commissioned, so there is no report to share.

  • SSO, SAML or SCIM

    Not yet

    Sign-in is email or Google, per person. No federation, no automated deprovisioning.

  • High availability and an uptime SLA

    Not yet

    One application server. No failover and no contractual uptime figure.

  • Forensic watermark

    Off by default

    Built and switched off: the first version left a visible artefact.

  • Contracts, DPA and invoicing

    On request

    Not self-serve. A person works through them with you.

  • Security questionnaire

    On request

    We fill yours in, and the answers match this page, including the rows that say no.

Where your data lives

In plain words, from our privacy policy and subprocessor list.

  • Stored in the EU

    Account records and media are on our server in Helsinki, Finland, mirrored to object storage in Stockholm, Sweden. Exports are stored alongside them. Privacy, section 5

  • AI processing goes abroad

    To answer an instruction we send text, and sometimes sampled video frames, to AI providers in the United States, Singapore and China. Every one is named, with what it receives. AI providers

  • Not used to train models

    We do not use your videos, audio, images, transcripts or projects to train generative AI models, and do not let providers do so with what we send them. Privacy, section 3

  • One adjacent thing, stated plainly

    When an agent run succeeds we may keep the sequence of editing commands it produced, with its instruction, to plan better next time. Never your media. Ask and we exclude your runs. How it works

  • Some work never leaves the browser

    Visual labelling and silence detection run on your own machine. Transcription runs on our servers or in your browser, not at a third party. Privacy, section 4

  • Retention you can read

    Your work stays until you delete it. Unreferenced uploads go after 72 hours, deleted media leaves the backup store within 30 days, API request logs after 30 days. Retention table

Who processes data for us

GroupCompaniesWhere
InfrastructureHetzner, Amazon Web Services, Vercel, Google Firebase AuthenticationFinland, Sweden, United States
AI model providersOpenAI, Alibaba Cloud (Qwen), DeepSeek, xAI, Google (Gemini)United States, Singapore, China
Payments, email and operationsDodo Payments, Paystack, Customer.io, Sentry and othersUnited States, EU and others
Only if you use themSocial platforms you publish to, chat apps, stock libraries, plugins you installVarious

What we can send you

Only documents that exist or that we can produce.

  • Data processing agreement

    On request

    Ask and we work through one with you. Not a click-through, and we will say what we cannot commit to.

  • Completed security questionnaire

    On request

    Send yours. The answers will match this page.

  • Company registration

    Available

    Buzz Innovations Ltd, company 17212684, on the public register at Companies House.

  • Invoices with bank details

    On request

    Numbered invoices with payment details and your PO reference, for annual Enterprise terms.

  • Subprocessor list

    Available

    Every company that processes customer data, by name, with what it receives and where.

  • SOC 2 report or pen test report

    Not yet

    Neither exists, so neither can be shared.

Report a vulnerability

Use the contact form, or email support@s-ticketing.vidmoat.com with “security” in the subject. Both open a ticket that a person reads, usually the same day.

Say what you found and how to reproduce it, and give us a chance to fix it before you publish. There is no bug bounty programme yet.

Changes to this page

  1. Trust page rebuilt: controls grouped, a status grid for what we do not have, documents on request, where your data lives, and this changelog.

Is an empty row blocking you?

Tell us which one, and we will say honestly whether it is weeks or quarters.