Project security

Agree on handling before sharing sensitive work.

Security controls, transfer methods, file retention, access requirements, and confidentiality needs are reviewed as part of project scoping. This page does not claim certifications or controls that have not been separately confirmed.

Before sharing sensitive materials

Tell us about confidentiality, access, residency, retention, deletion, or NDA requirements before sending files. Do not submit regulated, highly sensitive, export-controlled, or legally restricted information until the handling approach and any project-specific obligations are agreed in writing.

Current transfer limits

The standard in-app upload path is limited to supporting files up to 25 MB. It is not represented as a secure, production-ready transfer path for multi-gigabyte footage or large source-video libraries.

Direct signed uploads to Cloudflare R2 or another S3-compatible object store are planned but remain a TODO until the storage, access, expiry, validation, and operational controls are implemented and verified. For large files, agree on an access-controlled transfer or share-link method with the production team before uploading.

Links, passwords, and credentials

Restrict external share links to the intended recipients when the provider allows it, apply an expiry date when appropriate, and remove access after handoff. Do not place account passwords, API keys, storage credentials, recovery codes, or other secrets inside project briefs, filenames, comments, or uploaded documents.

If project work requires access to another system, the access method, permissions, and removal process should be arranged separately and limited to the agreed task.

Access, retention, and delivery

Project scope can document who needs access, how review copies are shared, how final deliverables are released, and whether a specific retention or deletion schedule is required. Customers should download and safeguard final deliverables within the agreed availability period.

Report a concern

Use the contact page to report a suspected exposure, incorrect share permission, unexpected access, or other security concern. Include the project number and enough detail to identify the affected material, but do not place passwords or other secrets in the message.