Security · Overview

Security

How we protect customer accounts and the video content you upload to Post Slate. Authoritative legal terms live in the Privacy Policy §12; this page is the operational summary.

Data in transit

All traffic between your browser, the marketing site, and the app is encrypted using TLS 1.2 or higher. HTTP Strict Transport Security (HSTS) is enabled with a two-year max-age and `includeSubDomains` so browsers refuse to downgrade. We do not accept plaintext HTTP connections.

Data at rest

Uploaded video Content and generated Output (VTT, AD script, MP3) are stored in a private Supabase storage bucket and encrypted at rest using AES-256. Database records (account, job metadata, billing references) are encrypted at rest by the underlying managed Postgres provider.

Access control

Retention & automatic deletion

Uploaded video files and Output files are automatically deleted 30 days after the associated Processing Job completes. Job metadata (job ID, status, timestamps) is retained for up to 12 months for billing and audit purposes. Account information is retained for the life of the account. Full retention schedule is in the Privacy Policy §7.

Sub-processors

Post Slate uses the following sub-processors to deliver the Service. The complete table — including data categories transferred and training opt-out status for each — lives in the Privacy Policy §5.

Vulnerability reporting

If you discover a security vulnerability, please report it to hello@postslate.com with subject [SECURITY]. We will acknowledge within 48 hours. We do not currently run a paid bug bounty, but we will credit researchers in our public disclosure if requested.

Please do not publicly disclose a vulnerability before we've had a reasonable window to investigate and ship a fix. We commit to working in good faith with reporters who operate under coordinated disclosure norms.

Compliance roadmap

Breach notification

In the event of a confirmed data breach affecting your personal information or Content, we will notify affected customers as required by applicable law and, in any case, within 72 hours of discovery if the breach is likely to result in a risk to your rights or interests.

For a copy of our security questionnaire or vendor-review documentation, contact hello@postslate.com.
© 2026 Post Slate · All rights reserved WCAG 2.1 AA · 256-bit TLS · SOC 2 on roadmap