Security
Kraftflix is built for the standards a studio answers to. Production scripts, unreleased footage and cast data are sensitive — we protect them with encryption, least-privilege access, and a security programme aligned with recognised frameworks.
ISO 27001 and SOC 2 Type II certification are underway. AES-256 encryption is active today.
Data protection
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for project data, media assets and backups.
- Private-by-default projects — generated outputs are visible only to the creator and the collaborators they explicitly invite.
- Watermarking and export controls on shared review links; assets marked restricted are excluded from exports automatically.
- Your content is never used to train models we make available to other customers or the public — see the Privacy Policy.
Access & identity
- Role-based access across organisation workspaces (owner, admin, member, reviewer), with reviewers unable to generate, edit, or spend credits.
- Least-privilege internal access to customer data, with access logging.
- SSO for organisation plans, available on request.
Infrastructure & monitoring
- Segregated production environments, regular backups, and continuous monitoring for anomalous activity.
- Subprocessors are reviewed before onboarding; organisation admins are notified in advance of a new subprocessor with access to their data.
- Independent penetration testing at least annually, once the current product surface stabilises post-launch.
Incident response
We maintain an incident-response process aligned with the Digital Personal Data Protection Rules, 2025 — including reporting significant personal-data breaches to the Data Protection Board of India and affected users within the timelines the Rules require. If you discover an incident affecting your data, we'll notify you directly and work with you on remediation.
Support & availability
We aim to respond to support requests within 1 business day; Organisation plans get priority queues. For status and incident updates, we notify affected users directly and, for anything material, post an update here.
Organisation (Studio) plans carry a target of 99.9% uptime, measured monthly and excluding scheduled maintenance (which we notify admins of in advance). Formal service-credit terms for missed targets are set out in the Enterprise agreement for Studio and Enterprise customers — see below.
Enterprise trust documents
For studios and institutions, a Data Processing Addendum (DPA), the current subprocessor list, and a formal SLA are available on request at hello@dimensionleap.com. Our ISO 27001 certificate and SOC 2 Type II report will be published here once each audit is complete.
Report a vulnerability
Found a security issue? Email hello@dimensionleap.com with details and, if possible, steps to reproduce. We investigate every report, ask that you give us a reasonable window to fix an issue before public disclosure, and won't pursue legal action against good-faith, non-destructive testing reported to us privately.