This page is written to be read end to end by a CISO or a DPO. Everything below is taken from documents that already bind us: the Data Processing Agreement and the privacy policy.
No actual transfer of data outside the European Union takes place. Some of our subprocessors are headquartered outside the EU, but the servers that process your data are not: AI processing runs in France at Mistral, and the database and the application are served from within the European Union. That is what puts us beyond the reach of the Cloud Act.
| Subprocessor | Role | Servers |
|---|---|---|
| Mistral AI | Transcription, analysis and generation | France |
| Supabase | Database, authentication, file storage | European Union (Frankfurt) |
| Vercel | Application hosting | European Union (Frankfurt) |
The complete, up-to-date list of subprocessors, including their country of incorporation, is set out in the Data Processing Agreement.
It is the first clause we write into the contract, because it is the first question we are asked.
The know-how you record does not feed the training of our models.
It is never pooled with other customers' data.
It is used to provide you with the service, and for nothing else.
The measures below are the ones in place, not the ones planned. Every line can be checked in the data processing agreement or in the application itself.
Encryption is not a configuration option and isolation is not a promise: both are in the code, on every table and for every account.

Who did what, when, and what happens if everything goes down. Those are the two questions an audit asks, and the answers here are figures, not adjectives.

The Data Processing Agreement is public on this site. You can read it before speaking to us, and have your legal team review it without asking us for a copy.
You are the controller, ClipHow is the processor within the meaning of Article 28. The Data Processing Agreement is published and can be signed as it stands.
Access, rectification, erasure, portability, restriction and objection. We assist you with every request, and the DPO can be reached directly.
The list is published in the DPA. Any change is notified to you in writing with 30 days' notice, which leaves you time to object.
Data is retained for the duration of the contract, then deleted within 30 days of its end, save where the law requires otherwise.
No recording enters the knowledge base without approval: yours, a manager's, or that of the people you have designated. Nothing publishes itself.
For environments that cannot let their data leave their own infrastructure, a deployment inside your walls is possible. The scope is discussed case by case.
At the end of the contract, a full export in a structured format (JSON / ZIP) within 30 days, permanent deletion after that, and a certificate of destruction on request.
Every approval, every publication and every access change is written to the audit log. You can reconstruct who let what into the base, and when.
A security page that overstates its position costs the deal it was meant to unblock: your CISO reads it next to the contract. So here is the real state of things, dated.
Not certified to date. Our information security management system is aligned with the standard (security policy, continuity plan, incident response, risk register, access reviews) and the Stage 2 audit is planned for the fourth quarter of 2026.
Targeted for the second quarter of 2027 in our own name. Our infrastructure sub-processors — Supabase, Vercel, Mistral — are already SOC 2 Type II; their reports can be shared under NDA.
An internal test suite (seven modules, cross-tenant access included) and a Row Level Security audit have been carried out. The external PASSI penetration test is scoped but has not started yet: we would rather write that down than let it be assumed.
Your team can audit and penetration-test a dedicated test tenant, whenever they want. A completed security questionnaire (CAIQ-style, or your own) is available on request from the DPO.
Detailed policies, our sub-processors' SOC 2 reports, the Row Level Security audit and the incident response plan are shared under NDA.
Not in our own name, to date. Our information security management system is aligned with ISO 27001:2022 and the Stage 2 audit is planned for the fourth quarter of 2026; SOC 2 Type 2 is targeted for the second quarter of 2027. Our infrastructure sub-processors are already SOC 2 Type II, and their reports can be shared under NDA.
Never. It is written into the data processing agreement: your know-how does not feed the training of our models, it is not pooled with other customers, and it serves nothing other than providing you the service.
Inside the European Union. AI processing runs in France at Mistral; the database, authentication and storage are at Supabase and the application at Vercel, both served from inside the European Union. No actual transfer outside the EU is taking place, which puts us beyond the reach of the Cloud Act.
Yes, on a dedicated test tenant, whenever your team wants. On our side, an internal test suite — seven modules, cross-organisation access included — and a Row Level Security audit have been carried out. The external PASSI penetration test is scoped but has not started yet.
Everything. A complete export in a structured format (JSON / ZIP) within 30 days, permanent deletion after that, and a destruction certificate on request. Your know-how is yours: all you lose is access to the platform.