GDPR
Processing under a data processing agreement (Art. 28 GDPR), EU data residency.
Your episodes reach us before anyone else sees them. This page shows how we protect them, what is already in place and what we are working on.
Last reviewed:
Cloud operation and storage in EU data centers. OnPremise keeps everything in your network.
Episodes, transcripts and clips are never used to train AI models.
Unreleased content stays locked to authorised users, with a log of every access.
Nothing is published without sign-off from your editors.
We are honest about where we stand. Certifications are listed as planned until the audit is passed.
Processing under a data processing agreement (Art. 28 GDPR), EU data residency.
Information security management system, certified by an accredited body.
Independent audit of security and availability controls over time.
Cloud security catalogue of the German Federal Office for Information Security, relevant for public broadcasters.
Grouped by what matters most to media companies. Each control shows its current status.
Embargo protection
Episodes are only visible to the users and roles you assign until the release date.
File access log
Every view, download and export of a file is logged with user and time.
Expiring review links
Share clips for review via links that expire and can be revoked at any time.
Watermarked previews
Review copies carry a visible watermark naming the viewer.
No training on customer content
Your uploads, transcripts and generated assets are never used to train or improve AI models, ours or third parties'.
Human in the loop
AI suggests, your editors decide. Clips are only published after approval.
Model processing in the EU
AI inference for the cloud runs in the EU. OnPremise runs all models inside your network.
No retention by model providers
Where third-party models are used, contracts exclude storage and training on your data.
EU AI Act
Transparency obligations assessed and implemented, including labelling of AI-generated content where required.
EU hosting
Cloud data is stored and processed exclusively in EU data centers.
Data processing agreement
Standard DPA under Art. 28 GDPR available for every customer.
Retention and deletion
Defined retention periods, deletion on request and complete deletion at the end of the contract.
Subprocessor notice
Advance notice of new subprocessors, with the right to object.
Single sign-on
SAML 2.0 and OpenID Connect with your identity provider.
SCIM provisioning
Users and groups are created and removed automatically from your directory.
Roles and permissions
Fine-grained permissions per project, from viewer to approver to admin.
Audit logs
Traceable history of every login, permission change and approval.
Multi-factor authentication
MFA for all accounts, enforceable per workspace.
Encryption in transit
TLS 1.3 for all connections.
Encryption at rest
AES-256 for stored media, transcripts and metadata.
SLA
Contractual availability for enterprise customers.
Tenant isolation
Customer data is logically separated, with separate storage per workspace.
Backups and recovery
Encrypted backups with regularly tested restores.
Public status page
Live availability and incident history.
Responsible disclosure
A clear channel for security researchers, with acknowledgement of valid reports.
Secure development
Mandatory code review, separate environments and no production data in testing.
Dependency scanning
Automated scanning of code and dependencies for known vulnerabilities.
Annual penetration test
Independent third-party test of the platform, summary available under NDA.
Kubernetes and Helm
Standard deployment into your cluster or private cloud.
Air-gapped operation
Runs without any internet connection, including all AI models.
Signed releases
Container images are signed so you can verify their origin.
SBOM per release
A software bill of materials ships with every version.
Cyber Resilience Act
Vulnerability handling and security updates in line with the EU Cyber Resilience Act.
Incident response
Documented incident process and notification of affected customers without undue delay.
Confidentiality
Everyone with access to customer content is bound by confidentiality agreements.
Security awareness
Regular security training for the whole team.
Third parties that process customer data on our behalf. OnPremise installations use none of them.
| Purpose | Provider | Location |
|---|---|---|
| Cloud hosting and storage | Published before launch | EU |
| AI inference (transcription, analysis) | Published before launch | EU |
| Transactional email | Published before launch | EU |
| Payments (Creator plan) | Published before launch | EU |
| Customer support | Published before launch | EU |
We welcome reports from security researchers acting in good faith. Please send details to the address below and give us reasonable time to fix the issue before disclosing it. We do not take legal action against good-faith research.
Yes. We have a completed standard questionnaire (CAIQ / SIG Lite) and answer custom questionnaires as part of every enterprise evaluation.
In the cloud, exclusively in EU data centers. With ShowBits OnPremise, data never leaves your infrastructure.
Only for processing, under contracts that exclude storage and training. If you connect your own AI accounts, your contract with that provider applies to that processing. OnPremise uses no external AI services at all.
You can export everything. Afterwards all content, including backups, is deleted within the agreed period.
Enterprise customers can request an audit or a call with our security team as part of the contract.