Security

Security at RedactFlow

Your data security is our top priority. Here's how we protect your content.

🔒

Encryption in Transit

All data is encrypted using TLS 1.3. API communications, file uploads, and video downloads are fully encrypted end-to-end.

🛡️

Encryption at Rest

Video files and database records are encrypted using AES-256 server-side encryption on AWS S3 and RDS.

🔑

Authentication

JWT-based authentication with bcrypt password hashing (12 rounds). Multi-factor verification via email and phone during signup.

🚫

Access Controls

Role-based access control for team features. API keys with scoped permissions. Session management with configurable expiry.

📊

Audit Logging

Every action is logged — file uploads, detection reviews, exports, and account changes. Full audit trail for compliance.

🏗️

Infrastructure

Hosted on AWS with VPC isolation, security groups, and private subnets. GPU processing runs in isolated containers on Modal.

Compliance

HIPAA

Business Associate Agreements available. Audit-ready compliance reports for healthcare video.

GDPR

EU data processing compliant. Data deletion on request. Privacy by design architecture.

SOC 2

Security controls aligned with SOC 2 Type II requirements. Regular third-party audits.

Video data lifecycle

1

Upload

Video encrypted in transit via TLS 1.3, stored encrypted (AES-256) on S3.

2

Processing

Processed in isolated GPU containers. No persistent storage — temp files deleted after processing.

3

Storage

Redacted video and reports stored encrypted. Retention based on your plan (7–90 days).

4

Deletion

Automatic deletion after retention period. Immediate deletion available on request.

Found a vulnerability?

We take security seriously. Please report any vulnerabilities responsibly.

Report a Vulnerability →