> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://knowledge.autocut.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# What is AutoCut’s security policy?

*Last updated: August 14, 2025*

AutoCut is designed for professional editors who care about speed **and** data protection. This page explains how we secure your content and account data across our plugin, services, and websites.

# How AutoCut processes your data (local vs. cloud)
* **Local-first:** Many operations run **directly on your machine** inside Premiere Pro or DaVinci Resolve.
* **Secure cloud processing (when needed):** Some features (e.g., AI analysis) may require a short, encrypted round-trip to our servers.
* **Automatic cleanup:** When cloud processing is used, **temporary files are deleted after the job completes**. We keep only minimal operational metadata (e.g., job IDs, timestamps) for reliability, support, and abuse prevention.

|| 💡 Need to allow network access on company devices? See: [Which domains should be whitelisted for AutoCut](https://knowledge.autocut.com/en/article/which-domains-should-be-whitelisted-for-autocut-1xc1elm/)

# Data we may process
* **Media you choose to process** (audio/video segments)
* **Generated assets** (e.g., transcripts, captions, preview files)
* **Project metadata** (duration, language, basic technical info)
* **Account & billing** (email, plan; payments handled by Stripe)
* **Diagnostic logs & crash reports** (anonymized where possible; used to improve stability)
We **never sell** customer data. We **do not** use customer data for AI training.

# Encryption & network security
* **In transit:** All connections use **HTTPS (TLS 1.2+)**.
* **At rest (cloud):** Data stored in our cloud services is protected with **industry-standard encryption**.
* **Ports:** Outbound **443/TCP** is required for AutoCut services and updates.

# Access control & identity
* **Least-privilege access:** Employee access is granted on a **need-to-know** basis with role-based permissions.
* **Strong authentication:** Administrative systems require **multi-factor authentication**.

# Application security & SDLC
* **Secure development lifecycle:** Code reviews, dependency scanning, and CI checks before production deploys.
* **Vulnerability management:** Regular patching, security scanning, and prompt remediation based on severity.

# Monitoring, logging & backups
* **Monitoring & alerting:** 24/7 observability for availability, performance, and security signals.
* **Audit logs:** Administrative and production changes are logged.
* **Backups:** Core configuration and operational data are backed up to support disaster recovery. Temporary job artifacts are **not** retained after processing completes.

# Incident response & business continuity
If we detect a security issue affecting customer data, we will:
1. **Contain and remediate** (e.g., revoke keys, rotate secrets, patch systems).
2. **Notify affected customers** with details and next steps.
3. **Perform root-cause analysis** and implement improvements.
4. **Document & review** the incident to prevent recurrences.
Our business continuity and disaster recovery procedures are**&#32;updated regularly**.

#  Privacy & compliance
* We follow **data-minimization** and **purpose-limitation** principles.
* We honor **user access & deletion requests** where applicable.
* We work to support organizational compliance needs (e.g., GDPR principles) and can provide additional details under NDA if required by your vendor review.

# Subprocessors & third-party services
To operate AutoCut, we use reputable providers for specific functions, for example:
* **Stripe** – payment processing
* **Sentry** – error & crash reporting
* **Cloud hosting/CDN & object storage** – secure infrastructure for updates, assets, and short-term processing artifacts
A current list of essential domains is available in: [Which domains should be whitelisted for AutoCut?](https://knowledge.autocut.com/en/article/which-domains-should-be-whitelisted-for-autocut-1xc1elm/)

# Customer responsibilities (enterprise IT)
* Allow outbound HTTPS (443) to AutoCut service domains.
* Keep **Premiere Pro / DaVinci Resolve** and the **AutoCut plugin** up to date.
* Limit local workstation access to authorized users; enable OS-level disk encryption where possible.

# Reporting a vulnerability
If you believe you’ve found a security issue, please contact us:
* **Email:** contact@autocut.com
* **Include:** a detailed description, reproduction steps, impact, affected environments, and any logs/video that help us verify.
* **Responsible disclosure:** Please give us reasonable time to investigate and fix before public disclosure.

