Security
Protect the account.
Protect the work.
Frame24 uses layered safeguards across identity, application access, infrastructure, storage, and public sharing.
Last updated 21 August 2026Our approach
Security is part of how Frame24 is designed and operated. We combine managed cloud infrastructure with application-level access checks, limited service credentials, operational monitoring, and controlled public-sharing routes. Controls continue to evolve with the product and its customers.
Current safeguards
Identity and account access
Authentication is handled through a dedicated identity provider. Signed-in product and project routes require an authenticated session, and server-side ownership checks protect customer resources.
Transport and storage
Frame24 uses HTTPS for data in transit. Customer assets and rendered media are stored on managed cloud storage, with provider-managed protections including encryption at rest. Access to operational systems and service credentials is restricted to what is needed to run the product.
Payments
Payments are processed by Stripe. Frame24 does not directly store complete payment-card details.
Public sharing
Public film links use high-entropy URLs and can be disabled by the owner. They are intentionally viewable without an account, so possession of the link grants viewing access. They should not be treated as a substitute for authenticated document sharing.
Service providers
Frame24 selects specialist providers for identity, infrastructure, payments, AI and media processing, storage, and email. Provider access is limited to the purpose for which the service is used.
Customer responsibilities
- Protect account credentials and use the security options offered by the identity provider.
- Grant access only to people who need it and report unexpected account activity promptly.
- Share public film links deliberately and disable links that are no longer required.
- Do not upload secrets or sensitive information that is unnecessary for producing a film.
Report a vulnerability
If you believe you have found a security issue, use our contact pageand choose the Security subject. Include the affected URL or component, steps to reproduce, impact, and a safe way to contact you.
Please act in good faith: avoid accessing or changing other people’s data, disrupting the service, using social engineering, or publishing details before we have had a reasonable opportunity to investigate. We will acknowledge legitimate reports and keep reporters informed as we assess them.
Security and procurement reviews
Organisations evaluating Frame24 can contact us for product architecture, data-flow, deployment, identity, and procurement discussions. Any contractual security commitment, data-processing agreement, residency option, or service level must be agreed in writing.
Frame24 does not claim a certification or audit unless it is expressly documented in a written agreement or published here.