Security Details
At our company, we take the security and privacy of our customers' data very seriously. We understand that our customers
trust us with their valuable data and we are committed to keeping it safe. In this article, we will provide you with
information about the locations of our servers that host customer data, our backup procedures, physical security
measures, firewalls, encryption, employee access to customer data, third-party penetration testing/audits, and our
policies and procedures regarding data protection infrastructure.
Locations of servers
All video files are hosted and encoded on servers located in France.
Company's backup procedures
We recognize how critical backups are for protecting your data. Our comprehensive backup system includes:
- Video Files
- Stored on object storage.
- Daily replication to a second server for added redundancy.
- Database
- Backed up every day using Write‑Ahead Log (WAL) continuous backup.
- Backups are saved to object storage on a separate server, ensuring that both the data and the storage location
are redundant and secure.
These layered backups give you confidence that your content is safe, even in the face of unforeseen events.
Physical security at our data centers
Our provider for video hosting and processing adheres to strict security standards and holds multiple industry
certifications. You can view the full list of certifications here:https://www.ovhcloud.com/en/compliance/
Firewalls
We take the security of our network very seriously. We have implemented platform-wide security rules to filter incoming
traffic and also use iptables on our servers to only allow necessary traffic. This ensures that our network is protected
from any unauthorized access.
Encryption
We understand the importance of encrypting data in transit to protect it from any potential threats. That is why we use
TLS 1.2 and 1.3 encryption to protect data in transit. This ensures that our customers' data is safe and secure while
being transferred over the internet.
Technical and organizational measures we use to restrict and regulate employee’s access to customer’s data
We have strict policies and procedures in place to regulate and restrict employee access to customer data. Customer data
can only be accessed through HTTPS over VPN for the managing application and SSH connections on servers. Only employees
who need to use one of these methods are granted access. Additionally, our management application logs provide employee
ID correlation with actions. This means that every interaction on data accessed or modified, as well as modifications to
the account, are logged for 60 days. This allows us to track any changes made to customer data and ensure its security.
Third-party penetration testing and audits
We understand the importance of regularly testing and auditing our security and privacy program. That is why we perform
an audit once a year by an independent third party. This ensures that our systems and procedures are up to date and
secure.
Policies and procedures regarding data protection infrastructure
As part of our commitment to protecting our customers' data, we have a Data Management Policy in place. This policy
classifies data into three categories: Public, Restricted, and Highly Restricted. Each classification requires different
access, management, and governance procedures. This ensures that our customers' data is handled with the utmost care and
security.
We hope this article has provided you with a better understanding of our company's security and privacy measures. If you
have any further questions or concerns, please do not hesitate to reach out to our customer support team.