Skip to main content

Security & Compliance FAQ (SOC 2, ISO 27001, Data Handling)

P
Written by Peace Aisosa

Common security and compliance questions from vendor and procurement reviews, answered below.

Do you hold SOC 2 or ISO 27001 certification?

Shotstack does not currently hold ISO 27001 or SOC 2 certification directly. Our infrastructure runs on AWS, and we rely on AWS's own ISO 27001 and SOC 2 Type II certifications for the underlying infrastructure layer (see our Data Processing Addendum, Annex 2).

We already operate to SOC 2-aligned security policies internally, and formal SOC 2 certification is on our near-term roadmap.

Do you use customer-submitted video or content to train AI/ML models?

No. Customer-submitted video and content is never used to train or fine-tune any ML model. Our Terms permit analysing Assets and API call data "for product development purposes" (clause 2.7), but that's limited to things like QA and aggregate usage analytics, not model training.

How long is my data retained, and can I request deletion?

  • Source media (footage, images, audio you provide for a render) is deleted immediately after the render completes.

  • Render payload JSON is retained as part of your render history. It can be deleted on request, and is automatically deleted for accounts inactive for 3+ months.

  • Output files are hosted on the Shotstack CDN by default. On completion, you also get a temporary link to the file valid for 24 hours — that expiry applies to the link, not the file itself. The file stays saved in our storage independently of that link, until you delete it (via the dashboard or API) or opt out of hosting entirely by adding "destinations": [{ "provider": "shotstack", "exclude": true }] to your render request, in which case nothing is persisted on our CDN after your own destination picks it up.

What application security practices do you follow?

Per our Data Processing Addendum (Annex 2), our practices include multi-factor authentication for production access, role-based access reviewed annually, encrypted credential storage, immediate access revocation on offboarding, TLS in transit and encryption at rest, and monitoring via AWS CloudTrail/Inspector.

We don't currently publish a separate secure-SDLC summary or run a formal vulnerability disclosure program or bug bounty. Security reports can be sent to [email protected] and are triaged directly.

What is your incident response process?

Our DPA commits to notifying customers without undue delay after becoming aware of a Personal Data Breach affecting their data (clause 4.7), backed by a documented internal incident response procedure with defined escalation paths and post-incident review. We don't currently publish a standalone public incident response document.

Who are your sub-processors? Do any AI/ML vendors process customer content?

Our current sub-processor list is public at shotstack.io/sub-processors. For Customer Personal Data, that's Amazon Web Services (compute, storage, CDN) and Sentry (error monitoring) only. No AI/ML vendor is engaged as a sub-processor.

Have a question not covered here, or need documentation for a vendor review? Reach out to our team and we're happy to help.

Did this answer your question?