For IT, security and procurement

The AI video tool your security team approves

Most tools in this category were built for creators and retrofitted for companies. DemoRiff was built the other way round: zero training on customer data, regional processing, private rendering, SSO, SCIM, and an audit trail that satisfies a real review.

RECORDER
In transit
1,284
+12%
On-time rate
96.4%
+2.1%
Avg. dwell
3.2h
−18m
At risk
23
+4
Shipment
Route
ETA
Status
SHP-4821
Rotterdam → Chicago
2 days
On time
SHP-4822
Shenzhen → Long Beach
9 days
Delayed
SHP-4823
Hamburg → Newark
4 days
On time
SHP-4824
Busan → Oakland
12 days
At risk
REC 02:41 · 4K60
captured: click → #new-shipment · 00:02:38.412
What you are dealing with

The part nobody puts in the job description

01

Recordings contain your customers

A screen recording of your product is, by definition, a recording of real data. Most video tools treat that file the way they treat a holiday video.

02

Shadow IT has already started

Three teams are already using three different AI video tools on personal accounts, with your customer data in them, outside your DLP.

03

Model training terms are usually vague

“We may use your content to improve our services” is not a sentence your DPO will sign off on, and it is in most of these contracts.

The plays

How teams like yours actually use it

Zero training, stated plainly

Your media, transcripts and derived assets are never used to train any model — ours or a subprocessor's. It is in the DPA, not just the marketing page, and it applies on every plan including free.

Choose where the frames are processed

Pin capture, processing and storage to the US, EU or Australia. On Enterprise, render inside your own cloud account so the media never leaves your perimeter.

Identity that fits your stack

SAML 2.0 and OIDC SSO, SCIM provisioning and deprovisioning, enforced domain capture so personal accounts get absorbed, and role-based access down to the workspace.

An audit trail that answers questions

Every view, export, share, permission change and masking rule, streamable to your SIEM. When someone asks who shared the demo containing a customer's name, there is an answer.

The workflow

What a week looks like

  1. 01

    Security review

    SOC 2 report, pen test summary, architecture diagram and a completed CAIQ on request.

  2. 02

    Contracting

    Your MSA or ours, a DPA with SCCs, and a subprocessor list with change notification.

  3. 03

    Deployment

    SSO, SCIM, domain capture, masking policies and region pinning configured before rollout.

  4. 04

    Consolidation

    Absorb the shadow-IT accounts, migrate their libraries, and turn on the audit stream.

Outcomes

What changes, measured

SOC 2 II
Audited annually
7 days
Median security review to approval
3 regions
US, EU, AU processing
99.9%
Uptime SLA on Enterprise
Security signed off in a week. Private rendering in our own VPC, no training on our frames, SOC 2 report on request. That is not a sentence I get to write about most AI vendors.
7 daysTo security approval
TATom AldridgeStaff Security Engineer · Halcyon
Questions

Common objections

The current list is published at demoriff.com/legal/subprocessors with the function each one performs and the region it operates in. Material changes are notified thirty days in advance, and Enterprise customers can object. Models used for transcription, translation and synthesis run under zero-retention agreements.

Yes, on Enterprise. We deploy the render workers into your AWS, GCP or Azure account, so media is processed and stored entirely within your perimeter. The control plane stays with us; the frames never leave you.

Enforced domain capture converts existing personal accounts on your domain into managed ones at next login, and bulk import brings their libraries across with transcripts intact. Most consolidations take under a week of elapsed time, and the migration is the easiest part of the conversation.