In Progress

Trust at Craftology

Your stories, scripts, and pre-release footage are some of your most valuable assets. Here is how we protect them — and the path we are on toward GDPR, SOC 2, and TPN.

Contact our trust team

Compliance status

We believe in transparency about where we are. The status below reflects active, in-progress work — not certifications we have not yet earned.

GDPRIn Progress

Lawful, transparent handling of EU/UK personal data — data-subject rights, a signable DPA, and a published subprocessor list.

Target: Q3 2026
SOC 2In Progress

Independent attestation that our security, availability, and confidentiality controls are designed and operating effectively.

Type I: Q4 2026 · Type II: Q2 2027
TPNPlanned

Trusted Partner Network assessment against MPA content-security best practices for handling pre-release studio assets.

Target: 2027

How we protect your work

Infrastructure security

  • Hosted on AWS with industry-standard physical and network controls
  • Data encrypted in transit (TLS) and at rest
  • Network isolation and least-privilege access to production
  • Automated, monitored backups

Data security & privacy

  • Your content is never used to train models without your explicit permission
  • Per-project data segregation
  • Defined retention with deletion and export on request
  • Data-subject request process aligned with GDPR

Access control

  • Authenticated access with MFA for administrative accounts
  • Role-based access on a least-privilege basis
  • Documented joiner / mover / leaver process
  • Production access is logged and reviewed

Application security

  • Mandatory code review and CI checks on every change
  • Dependency and vulnerability scanning
  • Third-party penetration testing (on the roadmap)
  • Coordinated vulnerability disclosure

Content security (TPN)

  • Purpose-built for pre-release film and creative assets
  • Secure, encrypted ingest and delivery of content
  • Per-project access boundaries
  • Watermarking, forensic tracking & chain-of-custody on the roadmap

Organizational & people

  • Confidentiality agreements for all staff and contractors
  • Security awareness training
  • Third-party / subprocessor risk review
  • Documented incident response plan

Documents & resources

Coming soon

SOC 2 reportOn the roadmap
Penetration test summaryOn the roadmap
Security whitepaperOn the roadmap

Enterprise security documentation will be available under NDA as our SOC 2 and TPN programs mature.

Your data, your rights

Wherever you are, you can exercise the following rights over your personal data. To make a request, email privacy@craftology.io.

Access a copy of your data
Correct inaccurate data
Delete your data
Export / port your data
Restrict or object to processing
Withdraw consent at any time
Lodge a complaint with a supervisory authority

Get in touch

Trust & compliance

Security questionnaires, documentation requests, partnerships.

legal@craftology.io

Privacy & data requests

Access, deletion, and other data-subject requests.

privacy@craftology.io

Report a vulnerability

Found a security issue? We want to hear from you.

security@craftology.io

Craftology is operated by ICVR LLC. This page describes our security and privacy program and current compliance roadmap; it does not constitute a warranty or certification. Status reflects work in progress.