Trust at Craftology
Your stories, scripts, and pre-release footage are some of your most valuable assets. Here is how we protect them — and the path we are on toward GDPR, SOC 2, and TPN.
Contact our trust teamCompliance status
We believe in transparency about where we are. The status below reflects active, in-progress work — not certifications we have not yet earned.
Lawful, transparent handling of EU/UK personal data — data-subject rights, a signable DPA, and a published subprocessor list.
Target: Q3 2026Independent attestation that our security, availability, and confidentiality controls are designed and operating effectively.
Type I: Q4 2026 · Type II: Q2 2027Trusted Partner Network assessment against MPA content-security best practices for handling pre-release studio assets.
Target: 2027How we protect your work
Infrastructure security
- Hosted on AWS with industry-standard physical and network controls
- Data encrypted in transit (TLS) and at rest
- Network isolation and least-privilege access to production
- Automated, monitored backups
Data security & privacy
- Your content is never used to train models without your explicit permission
- Per-project data segregation
- Defined retention with deletion and export on request
- Data-subject request process aligned with GDPR
Access control
- Authenticated access with MFA for administrative accounts
- Role-based access on a least-privilege basis
- Documented joiner / mover / leaver process
- Production access is logged and reviewed
Application security
- Mandatory code review and CI checks on every change
- Dependency and vulnerability scanning
- Third-party penetration testing (on the roadmap)
- Coordinated vulnerability disclosure
Content security (TPN)
- Purpose-built for pre-release film and creative assets
- Secure, encrypted ingest and delivery of content
- Per-project access boundaries
- Watermarking, forensic tracking & chain-of-custody on the roadmap
Organizational & people
- Confidentiality agreements for all staff and contractors
- Security awareness training
- Third-party / subprocessor risk review
- Documented incident response plan
Documents & resources
Available now
Privacy Policy→Terms of Service→Content Policy→Cookie Policy→Subprocessors→Data Processing Addendum (DPA)→Coming soon
Enterprise security documentation will be available under NDA as our SOC 2 and TPN programs mature.
Your data, your rights
Wherever you are, you can exercise the following rights over your personal data. To make a request, email privacy@craftology.io.
Get in touch
Craftology is operated by ICVR LLC. This page describes our security and privacy program and current compliance roadmap; it does not constitute a warranty or certification. Status reflects work in progress.