Security
How we protect the API, your credentials, and your content. Last reviewed: August 2026.
Reporting a vulnerability
- Email [email protected]. We acknowledge reports within 2 business days and aim to triage within 7.
- Please give us a reasonable window to fix before public disclosure. We do not pursue legal action against good-faith researchers who stay within the law and do not access other customers' data.
- Do not test against other customers' accounts, and do not run load tests against production without asking first.
Credentials & access
- API keys are stored as SHA-256 hashes. Full keys are shown once at creation and are not recoverable by us — or by anyone who reads the database.
- Dashboard sign-in is passwordless (single-use magic links); there are no stored passwords to leak.
- Production access is limited to the operators, over SSH with key authentication only.
Content handling
- All traffic is encrypted in transit (TLS). Video is fetched from your URLs over HTTPS wherever offered.
- Submitted media is never retained: image bytes live only in request memory; video frames are deleted within minutes of the verdict. Details: Trust & privacy.
- Webhook payloads are signed (HMAC-SHA256) so you can verify they came from us.
- Video source URLs are validated against SSRF: no redirects to private or link-local addresses.
Infrastructure
- API, queue, and video extraction run on Hetzner (EU). Inference runs on GPU hardware we operate. Your media is never shared with third-party AI providers.
- Dependencies are pinned and the image is rebuilt on every deploy; the public API surface is covered by an automated test suite including SSRF, quota, and auth cases.
- Media itself is never stored, so no database or backup can contain your content.
Incident response
- Security incidents: affected customers are notified by email within 72 hours of confirmation.
- Availability incidents: the public status page (/status.html) is updated as we learn, with a postmortem published within 48 hours of resolution for any significant outage.
- Our hash-match escalation procedure for known-illegal content is described on the trust page.
Compliance posture
- SafeReel is not SOC 2 certified today. We plan to pursue an independent assurance program when customer demand and company scale justify it — we will not claim otherwise.
- GDPR: a Data Processing Agreement is available on request for paid plans — email [email protected]. Subprocessors are listed on the trust page.