Articles on: Enterprise
This article is also available in:

What is AutoCut’s security policy?

Last updated: August 14, 2025


AutoCut is designed for professional editors who care about speed and data protection. This page explains how we secure your content and account data across our plugin, services, and websites.


How AutoCut processes your data (local vs. cloud)

  • Local-first: Many operations run directly on your machine inside Premiere Pro or DaVinci Resolve.
  • Secure cloud processing (when needed): Some features (e.g., AI analysis) may require a short, encrypted round-trip to our servers.
  • Automatic cleanup: When cloud processing is used, temporary files are deleted after the job completes. We keep only minimal operational metadata (e.g., job IDs, timestamps) for reliability, support, and abuse prevention.


💡 Need to allow network access on company devices? See: Which domains should be whitelisted for AutoCut


Data we may process

  • Media you choose to process (audio/video segments)
  • Generated assets (e.g., transcripts, captions, preview files)
  • Project metadata (duration, language, basic technical info)
  • Account & billing (email, plan; payments handled by Stripe)
  • Diagnostic logs & crash reports (anonymized where possible; used to improve stability)

We never sell customer data. We do not use customer data for AI training.


Encryption & network security

  • In transit: All connections use HTTPS (TLS 1.2+).
  • At rest (cloud): Data stored in our cloud services is protected with industry-standard encryption.
  • Ports: Outbound 443/TCP is required for AutoCut services and updates.


Access control & identity

  • Least-privilege access: Employee access is granted on a need-to-know basis with role-based permissions.
  • Strong authentication: Administrative systems require multi-factor authentication.


Application security & SDLC

  • Secure development lifecycle: Code reviews, dependency scanning, and CI checks before production deploys.
  • Vulnerability management: Regular patching, security scanning, and prompt remediation based on severity.


Monitoring, logging & backups

  • Monitoring & alerting: 24/7 observability for availability, performance, and security signals.
  • Audit logs: Administrative and production changes are logged.
  • Backups: Core configuration and operational data are backed up to support disaster recovery. Temporary job artifacts are not retained after processing completes.


Incident response & business continuity

If we detect a security issue affecting customer data, we will:

  1. Contain and remediate (e.g., revoke keys, rotate secrets, patch systems).
  2. Notify affected customers with details and next steps.
  3. Perform root-cause analysis and implement improvements.
  4. Document & review the incident to prevent recurrences.

Our business continuity and disaster recovery procedures are** updated regularly**.


Privacy & compliance

  • We follow data-minimization and purpose-limitation principles.
  • We honor user access & deletion requests where applicable.
  • We work to support organizational compliance needs (e.g., GDPR principles) and can provide additional details under NDA if required by your vendor review.


Subprocessors & third-party services

To operate AutoCut, we use reputable providers for specific functions, for example:

  • Stripe – payment processing
  • Sentry – error & crash reporting
  • Cloud hosting/CDN & object storage – secure infrastructure for updates, assets, and short-term processing artifacts

A current list of essential domains is available in: Which domains should be whitelisted for AutoCut?


Customer responsibilities (enterprise IT)

  • Allow outbound HTTPS (443) to AutoCut service domains.
  • Keep Premiere Pro / DaVinci Resolve and the AutoCut plugin up to date.
  • Limit local workstation access to authorized users; enable OS-level disk encryption where possible.


Reporting a vulnerability

If you believe you’ve found a security issue, please contact us:

  • Email: contact@autocut.com
  • Include: a detailed description, reproduction steps, impact, affected environments, and any logs/video that help us verify.
  • Responsible disclosure: Please give us reasonable time to investigate and fix before public disclosure.

Updated on: 29/09/2025

Was this article helpful?

Share your feedback

Cancel

Thank you!