Cask StudioTrust

Trust Center

How we protect your data today, and what is still in progress. Where something is not done yet, we say so.

Where your data lives

  • Our servers and databases run at Hetzner in Falkenstein, Germany. Your files are stored in Hetzner Object Storage, also in Germany.
  • We plan to move to Google Cloud in the Netherlands and Cloudflare R2 under its EU jurisdiction setting. Your data stays in the EU.
  • To generate media, we send your prompt and inputs to the AI provider you pick. Some of them process data in the US or Singapore. The subprocessor list names each one, where it runs and the transfer safeguard.
  • An organisation can turn on EU-only processing. Its jobs then use only models processed in the EU, and models without EU processing are hidden.

Encryption

  • Every connection uses TLS.
  • Passwords are hashed with argon2id.
  • MFA secrets are encrypted in the database with libsodium.
  • Files are reached only through signed links. A download link expires after 5 minutes.
  • Encryption at rest for storage and databases relies on our hosting provider today. Managed keys are planned.

Your account

  • You can turn on two-factor sign-in (MFA) with an authenticator app.
  • Sessions last 15 minutes and refresh on use. If a stolen refresh token is reused, we end every session in that chain.
  • Every request is limited to the data of the person who owns it.

For organisations

  • Enterprise single sign-on over OIDC or SAML 2.0, for example with Microsoft Entra ID, Okta or Google Workspace, for the email domains you verify. You can make it required. Signing in with SSO from the Mac apps is in beta.
  • SCIM provisioning: your identity provider adds, updates and removes members. Removing someone ends their access to the organisation at once.
  • An organisation audit log of sign-ins, member and role changes, settings changes and exports. Owners and admins can filter it and export it as CSV.

Our staff

  • One person has production access today.
  • The admin tools are not reachable from the internet.
  • Every admin change is logged.
  • Admin views of personal data are logged too. The log cannot be edited or deleted, and each entry is chained to the one before it by a hash, so tampering shows.

Export and erasure

  • Closing your account ends access at once and signs you out everywhere.
  • We erase a closed account within 90 days, including prompts, files and cloud projects. We keep accounting records for 7 years, as Dutch tax law requires.
  • You can export your account, projects, prompts, files and billing history as one ZIP. The export button is in the beta apps; until it reaches the stable apps, ask at [email protected].

Analytics on this site

This site loads no Google code until you click Allow on the cookie banner. If you decline, no request goes to Google. The Cookie Policy lists everything we store.

Labels on AI-generated media

In the beta versions of Cask Film and Cask Flow, every export that contains generated media is labelled as AI-generated in its metadata, using the IPTC digital source type. The stable apps get it with their next release. The EU AI Act asks for this label. Signed C2PA Content Credentials will follow.

Illegal content

Anyone can report illegal content through our report form, as the EU Digital Services Act requires. We send a statement of reasons for each removal, and the person affected can appeal.

Certifications

  • ISO 27001 and SOC 2 are in preparation. We hold neither today. Our security policies, risk register and Statement of Applicability are drafted.
  • An external penetration test of the API, admin tools and macOS apps is being booked.
  • Our hosting and AI providers hold their own certifications. Those cover their infrastructure, not Cask Studio.

Documents under NDA

For business customers, we share these under a non-disclosure agreement:

  • Our data processing agreement (DPA).
  • Our technical and organisational measures (TOMs).
  • Our answers to a standard security questionnaire.
  • The penetration test summary, once the test is done.

Ask at [email protected].

Contact

Security questions go to [email protected]. To report a vulnerability, read our disclosure policy first.