Security & compliance

Your know-how is sensitive. We treat it that way.

This page is written to be read end to end by a CISO or a DPO. Everything below is taken from documents that already bind us: the Data Processing Agreement and the privacy policy.

Where the data lives

A European stack, with no transfer outside the EU.

No actual transfer of data outside the European Union takes place. Some of our subprocessors are headquartered outside the EU, but the servers that process your data are not: AI processing runs in France at Mistral, and the database and the application are served from within the European Union. That is what puts us beyond the reach of the Cloud Act.

Subprocessors, their role and where their servers are
SubprocessorRoleServers
Mistral AITranscription, analysis and generationFrance
SupabaseDatabase, authentication, file storageEuropean Union (Frankfurt)
VercelApplication hostingEuropean Union (Frankfurt)

The complete, up-to-date list of subprocessors, including their country of incorporation, is set out in the Data Processing Agreement.

Contractual commitment

Your recordings train no model. Ever.

It is the first clause we write into the contract, because it is the first question we are asked.

No training

The know-how you record does not feed the training of our models.

No pooling

It is never pooled with other customers' data.

One use only

It is used to provide you with the service, and for nothing else.

Technical measures

Encryption, access control and traceability.

The measures below are the ones in place, not the ones planned. Every line can be checked in the data processing agreement or in the application itself.

Encryption and access

Encryption is not a configuration option and isolation is not a promise: both are in the code, on every table and for every account.

  • AES-256 encryption at rest and TLS 1.2 or above in transit, with HSTS preload
  • Multi-factor authentication mandatory for owners and administrators, available to everyone
  • Row Level Security isolation on every table, and four levels of roles
  • 15-minute session expiry and account lockout after repeated failures
  • SSO / SAML and SCIM provisioning on the Enterprise plan
The ClipHow security screen: two-factor authentication enabled, SSO / SAML configured, SCIM provisioning active, 15-minute session expiry and four levels of roles.
Traceability and recovery

Who did what, when, and what happens if everything goes down. Those are the two questions an audit asks, and the answers here are figures, not adjectives.

  • Audit log of every sensitive action, write-protected and kept for at least 12 months
  • Automated daily check of tenant-isolation invariants between organisations, with an alert on any deviation
  • Daily backups: RPO of 24 hours or less, RTO of 4 hours
  • Last successful restore test on 12 June 2026
  • Access review every 90 days, on the record
The ClipHow audit log: five time-stamped actions with their author and scope, and a CSV export button.
GDPR

What the contract already says.

The Data Processing Agreement is public on this site. You can read it before speaking to us, and have your legal team review it without asking us for a copy.

Roles and contract

You are the controller, ClipHow is the processor within the meaning of Article 28. The Data Processing Agreement is published and can be signed as it stands.

Data subject rights

Access, rectification, erasure, portability, restriction and objection. We assist you with every request, and the DPO can be reached directly.

Subprocessors

The list is published in the DPA. Any change is notified to you in writing with 30 days' notice, which leaves you time to object.

Retention

Data is retained for the duration of the contract, then deleted within 30 days of its end, save where the law requires otherwise.

Governance

You stay the gatekeeper of your knowledge base.

Approval before publication

No recording enters the knowledge base without approval: yours, a manager's, or that of the people you have designated. Nothing publishes itself.

On-premise deployment

For environments that cannot let their data leave their own infrastructure, a deployment inside your walls is possible. The scope is discussed case by case.

Exit and reversibility

At the end of the contract, a full export in a structured format (JSON / ZIP) within 30 days, permanent deletion after that, and a certificate of destruction on request.

Nothing is published without a trace

Every approval, every publication and every access change is written to the audit log. You can reconstruct who let what into the base, and when.

Audits and certifications

Exactly where we stand.

A security page that overstates its position costs the deal it was meant to unblock: your CISO reads it next to the contract. So here is the real state of things, dated.

ISO 27001:2022

Not certified to date. Our information security management system is aligned with the standard (security policy, continuity plan, incident response, risk register, access reviews) and the Stage 2 audit is planned for the fourth quarter of 2026.

SOC 2 Type 2

Targeted for the second quarter of 2027 in our own name. Our infrastructure sub-processors — Supabase, Vercel, Mistral — are already SOC 2 Type II; their reports can be shared under NDA.

Penetration testing

An internal test suite (seven modules, cross-tenant access included) and a Row Level Security audit have been carried out. The external PASSI penetration test is scoped but has not started yet: we would rather write that down than let it be assumed.

Check us yourself

Your team can audit and penetration-test a dedicated test tenant, whenever they want. A completed security questionnaire (CAIQ-style, or your own) is available on request from the DPO.

Detailed policies, our sub-processors' SOC 2 reports, the Row Level Security audit and the incident response plan are shared under NDA.

Security questions

What your CISO asks us, and what we answer.

Not in our own name, to date. Our information security management system is aligned with ISO 27001:2022 and the Stage 2 audit is planned for the fourth quarter of 2026; SOC 2 Type 2 is targeted for the second quarter of 2027. Our infrastructure sub-processors are already SOC 2 Type II, and their reports can be shared under NDA.

Never. It is written into the data processing agreement: your know-how does not feed the training of our models, it is not pooled with other customers, and it serves nothing other than providing you the service.

Inside the European Union. AI processing runs in France at Mistral; the database, authentication and storage are at Supabase and the application at Vercel, both served from inside the European Union. No actual transfer outside the EU is taking place, which puts us beyond the reach of the Cloud Act.

Yes, on a dedicated test tenant, whenever your team wants. On our side, an internal test suite — seven modules, cross-organisation access included — and a Row Level Security audit have been carried out. The external PASSI penetration test is scoped but has not started yet.

Everything. A complete export in a structured format (JSON / ZIP) within 30 days, permanent deletion after that, and a destruction certificate on request. Your know-how is yours: all you lose is access to the platform.

A question from your security team?

Write to our DPO directly, or let's spend half an hour with your CISO. We would rather answer before the question becomes a blocker in your procurement process.