Trust Center

Your episodes reach us before anyone else sees them. This page shows how we protect them, what is already in place and what we are working on.

Last reviewed:

EU only

Cloud operation and storage in EU data centers. OnPremise keeps everything in your network.

No training on your content

Episodes, transcripts and clips are never used to train AI models.

Embargo by default

Unreleased content stays locked to authorised users, with a log of every access.

Humans approve

Nothing is published without sign-off from your editors.

Compliance

We are honest about where we stand. Certifications are listed as planned until the audit is passed.

In place

GDPR

Processing under a data processing agreement (Art. 28 GDPR), EU data residency.

Planned

ISO/IEC 27001

Information security management system, certified by an accredited body.

Planned

SOC 2 Type II

Independent audit of security and availability controls over time.

Planned

BSI C5

Cloud security catalogue of the German Federal Office for Information Security, relevant for public broadcasters.

Security controls

Grouped by what matters most to media companies. Each control shows its current status.

Protecting unreleased content

  • Embargo protection

    Episodes are only visible to the users and roles you assign until the release date.

    In place
  • File access log

    Every view, download and export of a file is logged with user and time.

    In place
  • Expiring review links

    Share clips for review via links that expire and can be revoked at any time.

    Planned
  • Watermarked previews

    Review copies carry a visible watermark naming the viewer.

    Planned

AI and your data

  • No training on customer content

    Your uploads, transcripts and generated assets are never used to train or improve AI models, ours or third parties'.

    In place
  • Human in the loop

    AI suggests, your editors decide. Clips are only published after approval.

    In place
  • Model processing in the EU

    AI inference for the cloud runs in the EU. OnPremise runs all models inside your network.

    In progress
  • No retention by model providers

    Where third-party models are used, contracts exclude storage and training on your data.

    In progress
  • EU AI Act

    Transparency obligations assessed and implemented, including labelling of AI-generated content where required.

    In progress

Data protection

  • EU hosting

    Cloud data is stored and processed exclusively in EU data centers.

    In place
  • Data processing agreement

    Standard DPA under Art. 28 GDPR available for every customer.

    In place
  • Retention and deletion

    Defined retention periods, deletion on request and complete deletion at the end of the contract.

    In progress
  • Subprocessor notice

    Advance notice of new subprocessors, with the right to object.

    In progress

Identity and access

  • Single sign-on

    SAML 2.0 and OpenID Connect with your identity provider.

    In place
  • SCIM provisioning

    Users and groups are created and removed automatically from your directory.

    In place
  • Roles and permissions

    Fine-grained permissions per project, from viewer to approver to admin.

    In place
  • Audit logs

    Traceable history of every login, permission change and approval.

    In place
  • Multi-factor authentication

    MFA for all accounts, enforceable per workspace.

    In progress

Infrastructure and availability

  • Encryption in transit

    TLS 1.3 for all connections.

    In place
  • Encryption at rest

    AES-256 for stored media, transcripts and metadata.

    In place
  • SLA

    Contractual availability for enterprise customers.

    In place
  • Tenant isolation

    Customer data is logically separated, with separate storage per workspace.

    In progress
  • Backups and recovery

    Encrypted backups with regularly tested restores.

    In progress
  • Public status page

    Live availability and incident history.

    Planned

Application security

  • Responsible disclosure

    A clear channel for security researchers, with acknowledgement of valid reports.

    In place
  • Secure development

    Mandatory code review, separate environments and no production data in testing.

    In progress
  • Dependency scanning

    Automated scanning of code and dependencies for known vulnerabilities.

    In progress
  • Annual penetration test

    Independent third-party test of the platform, summary available under NDA.

    Planned

OnPremise

  • Kubernetes and Helm

    Standard deployment into your cluster or private cloud.

    In place
  • Air-gapped operation

    Runs without any internet connection, including all AI models.

    In place
  • Signed releases

    Container images are signed so you can verify their origin.

    Planned
  • SBOM per release

    A software bill of materials ships with every version.

    Planned
  • Cyber Resilience Act

    Vulnerability handling and security updates in line with the EU Cyber Resilience Act.

    In progress

Organisation

  • Incident response

    Documented incident process and notification of affected customers without undue delay.

    In progress
  • Confidentiality

    Everyone with access to customer content is bound by confidentiality agreements.

    In progress
  • Security awareness

    Regular security training for the whole team.

    Planned

Subprocessors

Third parties that process customer data on our behalf. OnPremise installations use none of them.

PurposeProviderLocation
Cloud hosting and storagePublished before launchEU
AI inference (transcription, analysis)Published before launchEU
Transactional emailPublished before launchEU
Payments (Creator plan)Published before launchEU
Customer supportPublished before launchEU

Documents

Public

  • Privacy policyView
  • Terms of serviceView
  • Data processing agreement (DPA)View
  • Subprocessor listView

On request, under NDA

  • Security whitepaper
  • Penetration test summary
  • OnPremise architecture and hardening guide
  • Completed security questionnaire (CAIQ / SIG Lite)

Request security documents

Tell us which documents you need. We send them after a short NDA, usually within two business days.

Documents

Information on how we process your data is in our privacy policy.

Found a vulnerability?

We welcome reports from security researchers acting in good faith. Please send details to the address below and give us reasonable time to fix the issue before disclosing it. We do not take legal action against good-faith research.

Security questions

Can you fill in our security questionnaire?

Yes. We have a completed standard questionnaire (CAIQ / SIG Lite) and answer custom questionnaires as part of every enterprise evaluation.

Where exactly is our data stored?

In the cloud, exclusively in EU data centers. With ShowBits OnPremise, data never leaves your infrastructure.

Do AI providers get access to our episodes?

Only for processing, under contracts that exclude storage and training. If you connect your own AI accounts, your contract with that provider applies to that processing. OnPremise uses no external AI services at all.

What happens to our data when the contract ends?

You can export everything. Afterwards all content, including backups, is deleted within the agreed period.

Can we audit ShowBits?

Enterprise customers can request an audit or a call with our security team as part of the contract.