HalcyonSecurity posture management480 employeesGlobal

Halcyon's security team approved an AI video tool in seven days

A company that sells security software has an unusually sceptical internal security team. Halcyon consolidated three shadow-IT video tools onto DemoRiff after a review that took a week rather than a quarter.

Enterprise governanceShadow IT consolidationRegional processingAudit
7 days
Security review to approvalAgainst a 6-week median for AI vendors
3 → 1
Video tools consolidatedTwo shadow-IT tools absorbed via domain capture
100%
Recordings with masking policy appliedEnforced at workspace level, not optional
0
Frames leaving their perimeterPrivate rendering in their own AWS account

“Security signed off in a week. Private rendering in our own VPC, no training on our frames, SOC 2 report on request. That is not a sentence I get to write about most AI vendors.”

TATom AldridgeStaff Security Engineer, Halcyon

Three tools nobody had approved

Halcyon's security team found what most security teams find when they look: marketing was using one AI video tool, customer education another, and a regional sales team a third — all on personal accounts, all containing recordings of a product that displays customer security findings on screen.

“The recordings were the problem, not the tools,” says Tom Aldridge. “A screen recording of our product is a recording of a customer's vulnerabilities. That file belongs under the same controls as the data itself, and it was sitting in three consumer SaaS accounts.”

What the review actually asked

Halcyon's review focused on four things: whether customer content could enter a training set, where frames are processed and stored, whether masking could be enforced rather than encouraged, and whether there was an audit trail that answered “who shared what.”

“The zero-training commitment being in the DPA rather than a blog post was the thing that moved fastest internally,” Aldridge says. “Most vendors have a marketing page that says one thing and a contract that says ‘to improve our services.’”

Halcyon deployed render workers into their own AWS account, so media is processed and stored entirely within their perimeter, with only the control plane hosted by DemoRiff.

“A screen recording of our product is a recording of a customer's vulnerabilities. That file belongs under the same controls as the data.”

Tom Aldridge · Staff Security Engineer, Halcyon

Consolidation was the easy part

Enforced domain capture converted the existing personal accounts into managed workspace accounts at next login. Bulk import brought their libraries across with transcripts intact. The whole migration took four days of elapsed time and no coordination meetings.

Workspace masking policies now apply to every recording automatically — emails, customer names, finding identifiers and API keys are masked before frames are encoded, and the people recording cannot turn it off.