Trust center

Your recordings contain your customers

A screen recording of your product is, by definition, a recording of real data. Most tools in this category were built for creators and retrofitted for companies. This one was built the other way round.

SOC 2 Type II

Current

Audited annually by an independent firm. Report available under NDA.

ISO 27001

Current

Certified information security management system.

GDPR

Compliant

DPA with Standard Contractual Clauses, EU representative appointed.

CCPA / CPRA

Compliant

Consumer rights honoured for all California residents.

HIPAA

Available

BAA available on Enterprise for covered entities.

VPAT / WCAG 2.2 AA

Current

Accessibility conformance report for the app and player.

Commitments

Six things we will not do with your content

Your content never trains a model

Media, transcripts, generated scripts and derived assets are never used to train any model — ours or a subprocessor's. Every model vendor we use operates under a zero-retention agreement, which means your frames are not retained after the inference call returns.

  • Stated in the DPA, not only in marketing material
  • Applies on every plan, including Free
  • Zero-retention agreements with every inference subprocessor
  • No human review of customer content without explicit, per-incident consent

Encrypted, scoped and deletable

AES-256 at rest, TLS 1.3 in transit, per-workspace key scoping and object-level access control. Deletion is real deletion: media is purged from primary storage, replicas and backups on a documented schedule, and we issue a signed certificate on request.

  • AES-256 at rest with per-workspace key scoping
  • TLS 1.3 in transit, HSTS enforced, no TLS below 1.2
  • Signed deletion certificates on request
  • Configurable retention policies per workspace

You choose where frames are processed

Pin capture, processing and storage to the United States, the European Union or Australia. On Enterprise, render workers deploy into your own AWS, GCP or Azure account, so media never leaves your perimeter — only the control plane is hosted by us.

  • US, EU and AU processing regions
  • Private rendering inside your own cloud account (Enterprise)
  • Regional pinning enforced at the workspace level
  • No cross-region replication without explicit configuration

Sensitive data masked before render

A screen recording of your product is a recording of your customers. Built-in detectors mask emails, phone numbers, card numbers, API keys, JWTs and common identifier patterns in-frame. Masking is applied at capture, so raw values never reach storage.

  • Detector, element, region and regex-based masking
  • Applied at capture — raw values never persist
  • Workspace policies that individual creators cannot disable
  • Audit record of every rule applied to every recording

Identity that fits your stack

SAML 2.0 and OIDC single sign-on, SCIM 2.0 provisioning and deprovisioning, enforced domain capture that absorbs personal accounts on your domain, and role-based access control down to individual workspaces.

  • SAML 2.0 and OIDC with any IdP
  • SCIM 2.0 provisioning, deprovisioning and group sync
  • Enforced domain capture for shadow-IT consolidation
  • Roles: owner, admin, creator, reviewer, viewer — per workspace

An audit trail that answers questions

Every view, export, share, permission change, masking rule and agent run is logged with actor, timestamp, IP and resource. Streamable to Splunk, Datadog, S3 or any SIEM over webhook, with a documented schema.

  • Immutable, append-only audit log
  • Streaming to Splunk, Datadog, S3 or webhook
  • Documented, versioned event schema
  • Retained 24 months, configurable up to 7 years
Operations

How we run the service

Penetration testing
Annual third-party test plus continuous automated scanning. Summary report available.
Vulnerability disclosure
Public programme at demoriff.com/security/disclosure with a 90-day coordinated window.
Uptime
99.98% trailing twelve months. 99.9% SLA on Enterprise. Public status page.
Backups
Continuous replication, point-in-time recovery to 35 days, quarterly restore drills.
Business continuity
Multi-region failover with a 4-hour RTO and 15-minute RPO.
Employee access
Least privilege, hardware-key MFA, quarterly access review, no standing production access.
Subprocessors
Published list with 30-day change notification and an Enterprise objection window.
Incident response
Documented plan, tabletop exercises twice yearly, 72-hour customer notification commitment.
Questions

What security teams ask

Need a questionnaire completed, a pen test summary, or a call with our security team? All three are routine and none of them require a sales process.

Contact security

No. Not on any plan, not in aggregate, not anonymised. Our contract says so in terms your legal team can rely on, rather than a general clause about improving our services. Every third-party model we call operates under a zero-retention agreement, meaning your content is not retained after the inference call completes.

The complete list, with the function each performs and the region it operates in, is published at demoriff.com/legal/subprocessors. Material changes are notified thirty days in advance, and Enterprise customers have a contractual right to object.

On Enterprise, render workers deploy into your AWS, GCP or Azure account. Media is captured, processed and stored entirely within your perimeter. The control plane — project metadata, permissions, the editing interface — remains hosted by us and never receives the media itself.

We maintain a completed CAIQ, SIG Lite and a standard questionnaire response pack, which we can send the same day. Custom questionnaires typically turn around in three to five business days. Median time from first security contact to approval across our Enterprise customers is seven days.

You can export everything — media, transcripts, guides, analytics — through the app or the API at any time, including after cancellation during a 90-day grace period. On request we delete everything and issue a signed certificate confirming purge from primary storage, replicas and backups.