Trust & Safety

Security & Data Protection

CineCLI runs on Amazon Web Services and accesses foundation models through Amazon Bedrock. This page describes the technical and organizational controls we use to protect customer accounts, content and data.

Last updated: June 13, 2026 · Version 1.0

Quick facts

Hosting
Amazon Web Services (AWS)
Model layer
Amazon Bedrock foundation models
Encryption
TLS 1.2+ in transit · AES-256 at rest
Region residency
Configurable to the selected AWS Region
Training on customer data
Never

1. Overview

Security is a foundational requirement of the CineCLI platform, not an add-on. We apply defense in depth across infrastructure, application, data and operational layers, and we follow the principle of least privilege throughout. Because synthetic media carries heightened safety risks, our security program is closely integrated with our content-safety controls — see our Responsible AI Policy.

2. Infrastructure

3. Encryption

4. Access control

5. Network & application security

6. Content safety controls

Security and content safety reinforce one another at CineCLI. Beyond protecting data, we screen what enters and leaves the platform:

The full safety model — including likeness, consent and deepfake rules — is described in our Responsible AI Policy and Acceptable Use Policy.

7. Data handling

8. Sub-processors

We use a limited set of vetted third-party providers to operate the service. The current list, their purpose and locations are published on our Sub-processors page, where you can also subscribe to change notifications.

9. Business continuity & incident response

10. Compliance & certifications

Our security program is designed to align with widely recognized control frameworks, and we build toward independent attestation as the platform matures. We design our handling of personal data to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) as further described in our Privacy Policy.

Operator note (remove before launch): State only frameworks and attestations actually held. Do not represent SOC 2, ISO/IEC 27001 or similar as obtained unless completed — describe in-progress work as "in progress" or "on our roadmap". Confirm which controls are independently audited and update this section with the legal entity name and audit dates before relying on it for review.

11. Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability, please contact security@cinecli.com with enough detail to reproduce the issue. We offer a good-faith safe harbor: we will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access or modify data beyond what is necessary to demonstrate the issue, and give us a reasonable opportunity to remediate before public disclosure.

12. Contact

For security questions, contact security@cinecli.com. For privacy and data-protection matters, contact privacy@cinecli.com. This page works together with our Privacy Policy, Sub-processors list and Responsible AI Policy.

Operator note (remove before launch): Confirm the legal entity name, the actual AWS Regions offered, key-management configuration, penetration-testing cadence, and breach-notification timelines required in your launch jurisdictions before publishing.