Where your data lives, who processes it, what we have been audited against, and how to reach us when something looks wrong.
Heimdall holds a small amount of data that matters a lot: your unreleased work. The architecture is deliberately boring — one primary region, encrypted object storage, no data warehouse of customer content, and no analytics vendor with access to it.
SOC 2 Type II covering security and availability, audited annually — report available under NDA. Penetration tested annually by an external firm, with the summary letter shared on request.
We are registered with the UK ICO as a data controller and act as processor for the studio content you upload.
Studio content is stored in the UK by default, with an EU region available on request. Generations are routed to the nearest available region a provider supports, and the region used is recorded on the generation in your ledger.
The list below is current. We publish additions at least 14 days before they take effect, so you have time to object.
Our standard Data Processing Agreement is available to sign for any plan, and includes the UK Addendum and EU Standard Contractual Clauses. Enterprise agreements can add custom retention windows, a named region and breach-notification timelines.
Point-in-time database backups with a 30-day window, restore-tested quarterly. Object storage is versioned and replicated within region.
Recovery objectives: RPO 1 hour, RTO 8 hours. Availability target for the app is 99.9% monthly, measured on the review and approval paths — the ones you cannot work without.
Confirmed incidents affecting your data are reported to you within 72 hours, with what happened, what was affected and what changed as a result. Live status and past incidents are published on our status page.
No training on your content, by us or by our providers — we use each provider’s no-training path where one exists, and note per-provider status in the subprocessor list.
Approval receipts are immutable: the candidate, brief version, input hash and cost recorded at approval cannot be edited after the fact, only superseded. That is what makes stale detection trustworthy.
Export everything from Settings at any time. Delete a piece and its candidates and receipts go within 30 days. Close the studio and everything but statutory ledger records goes with it.
Mail [email protected] — PGP key on request. We acknowledge within one business day, and we do not pursue good-faith research.