Legal

Security

Your clients trust your platform with their payments and their footage. These are the practices we build in as standard.

Last updated: 30 August 2026

1. Accounts in your name

Domain, hosting, and payment accounts are created in your name from day one. You hold the credentials, and any access we hold during the build can be revoked by you at any time.

2. Build practices

  • Traffic served over HTTPS, with secrets kept out of the codebase.
  • Authentication and access rules enforced on the server, never only in the browser.
  • Row-level access rules so one client can never read another client's records.
  • Least-privilege keys, rotated at handover.

3. Payments

Card details are handled by Stripe and never touch your platform's database. Payouts settle directly to your bank account.

4. Client uploads

Film and documents are stored behind authenticated, expiring links. Public buckets are not used for private client material.

5. Handover

At handover we transfer ownership of every account, remove our standing access unless you ask us to keep a support seat, and document where each credential lives.

6. Incidents

If we become aware of a breach affecting your platform during our engagement, we will tell you promptly, in writing, with what we know and what we recommend.

7. Reporting a vulnerability

We welcome responsible disclosure. A dedicated security contact is not published yet; until it is listed here, report findings on your call and give us reasonable time to fix before disclosing publicly. Do not test against live client data.

Questions about this policy?

We don't have a public support inbox yet. Until one is published here, raise any question directly on your intro call and we'll answer it in writing.