Snapshot 19495
Normalized text
Scripts and page chrome removed; this is what change detection compares.
All systems monitored — view status AI safety, security and trust at CaptionHub How we protect your video, captions and translation data. Certifications, policies and documentation for your security and procurement teams. Compliance Certifications SOC 2 Type II Verified Independently audited against the AICPA Trust Services Criteria for Security. The current Type II report is available on request under NDA. Request SOC 2 report ISO/IEC 27001:2022 Certified Certified by Citation ISO Certification (certificate no. 353082020, valid until 20 September 2027). Scope: the provision of AI-powered multimedia localisation of corporate multimedia assets. The current certificate is available on request. Request ISO 27001 certificate Responsible AI AI, models and trust CaptionHub is an embedded AI platform — it integrates third-party speech recognition and machine translation rather than training its own models. How we source, govern and oversee AI is set out in our Responsible AI policy and the FAQs below. Read the Responsible AI policy AI models and sourcing Does CaptionHub build or train its own AI models? No. CaptionHub is an embedded AI platform, meaning it integrates third-party foundational technologies to provide AI-enabled services such as automatic speech recognition and machine translation. CaptionHub does not design, develop or train its own artificial intelligence models. How are third-party AI services approved? Use of third-party AI services is permitted only after a review and approval by the CEO and CTO or CCO. Any approved third-party AI service is added to the CaptionHub Sub-Processor Register to maintain transparency and compliance with data processing regulations. Where can I find a list of the AI services CaptionHub uses? All integrated AI services are listed in the CaptionHub Sub-Processor Register. For information relating to the individual models themselves, we always recommend referring to the individual AI suppliers. How does CaptionHub vet its AI suppliers? Where the product incorporates third-party AI models or infrastructure, CaptionHub conducts due diligence to satisfy itself that those providers operate in a manner consistent with its own compliance obligations. Details of material third-party AI components are available on request. EU AI Act compliance How is CaptionHub classified under the EU AI Act? CaptionHub has assessed its AI system against the risk classification framework in Regulation (EU) 2024/1689 (the EU AI Act). The system falls within the limited risk category as defined under Article 50. It does not meet the criteria for high-risk classification under Annex III, nor does it constitute a general-purpose AI (GPAI) model as defined under Article 3(63). How often is this risk classification reviewed? The classification is reviewed on a regular basis, and in particular whenever material changes are made to the system's functionality, use cases, or deployment context. What transparency obligations does CaptionHub meet? As a limited-risk AI system, CaptionHub is subject to the transparency obligations of Article 50. In practice, this means users are informed when they are interacting with an AI system where this is not already evident from context, the system is never deployed in a manner designed to deceive users as to its nature, and appropriate disclosure mechanisms are in place where the system generates content that could be mistaken for human-produced output. Does the EU AI Act apply to customers outside the EU? Whilst the EU AI Act does not have direct legal force in the United Kingdom, CaptionHub has adopted its principles as the baseline standard for its global operations. It monitors developments under the UK government's AI regulation framework and will update its practices as statutory obligations emerge. For customers in the United States and other markets, this reflects a voluntary commitment to responsible AI development in the absence of equivalent binding regulation. Data privacy and training Is my data used to train AI models? CaptionHub only integrates AI services where there is either an option to opt out of data being used for AI training purposes, or an alternative service for a particular process (such as ASR). Where an opt-out is available, CaptionHub will always choose to opt out, in line with its commitment to protecting data and client privacy. How do I know which services have an opt-out in place? All opt-out options are labelled in the CaptionHub Sub-Processor Register. Governance and accountability How is the Responsible AI Policy kept up to date? The policy is reviewed regularly to ensure it remains aligned with current laws, technological advancements, and best practices in AI. Are employees trained on responsible AI? Yes. All employees receive training on the Responsible AI Policy to ensure understanding and compliance. Any violation of the policy may result in disciplinary action, up to and including termination of employment. What is CaptionHub's overall commitment to responsible AI? CaptionHub is committed to developing and deploying AI responsibly, prioritising transparency, fairness, and accountability in its AI-driven localisation solutions. It actively engages with industry best practices and continuously refines its technology to align with evolving ethical guidelines, fostering human-AI collaboration to empower users with accurate, inclusive, and responsible AI solutions. Further information Who do I contact about AI compliance? Customers seeking further information about CaptionHub's EU AI Act compliance position, or who require supporting documentation for their own procurement or regulatory processes, should contact compliance@captionhub.com. CaptionHub is happy to discuss specific requirements and, where appropriate, provide additional written confirmation. Human oversight Is there human oversight of AI outputs? Yes. The product includes an optional human-in-the-loop mechanism, enabling customers to introduce human review and approval at key stages of AI-assisted workflows. CaptionHub actively encourages the use of this feature, particularly in contexts where outputs may inform significant decisions. Documentation on configuring human oversight is available in the product knowledge base. Documentation Resources Security whitepaper Architecture, encryption, access control and operational security Download Responsible AI policy How AI is used in captioning, translation and voiceover — and its limits View Data Processing Addendum GDPR-compliant terms for processing personal data, including SCCs View SOC 2 Type II report Current attestation, available under NDA Request ISO 27001 certificate Current certificate and statement of applicability Request Data processing Sub-processors Third parties that process customer data on our behalf. The live register below is maintained at app.captionhub.com/page/subprocessors. Having trouble viewing? Open the register in a new tab Support Frequently asked questions Deployment and hosting Can I install my own instance of CaptionHub behind my firewall? Yes. For our Enterprise customers, CaptionHub can be deployed in a variety of ways. Please contact us for more details. Where is CaptionHub hosted? For a cloud install, CaptionHub hosts our applications and your data with Amazon Web Services (AWS). Physical and environmental security of the data centres is provided by AWS and covered by their SOC, ISO and PCI attestations. Does my data exist alongside other users? It depends on your install. For our multi-tenant customers, it does. CaptionHub is extremely well tested to ensure that users don't see each other's data, but if you require absolute separation, then we'd recommend you opt for our Single Tenant or On Premise installation options. Where is personal data stored? Customer data is hosted in the EU: our primary region is AWS eu-west-1 (Ireland), with a disaster-recovery environment in eu-central-1 (Frankfurt). Certifications and compliance What certifications does CaptionHub hold? CaptionHub is certified to ISO/IEC 27001:2022 and holds a SOC 2 Type II report covering the Security Trust Services Criteria. Our information security management system is reviewed through an internal and external audit programme and a system of continual improvement. How does CaptionHub handle international data transfers? We ensure compliance with GDPR and other cross-border regulations when transferring data via EU Standard Contractual Clauses (SCCs) plus the UK Addendum, and the UK's International Data Transfer Agreement (IDTA) where appropriate. Who oversees security governance? A Security Working Group oversees information risk and security management, with clearly assigned roles: a Chief Information Security Officer responsible for security operations, a Chief Compliance Officer responsible for certifications and conformity, and board-level accountability for information risk held by our CEO as Senior Information Risk Owner. Our Information Security Policy and supporting policies are reviewed at least annually and on significant change. Encryption Is data encrypted in transit? Yes. All traffic is encrypted in transit with TLS 1.2 or higher, using forward-secrecy cipher policies at our load balancers and CDN. Is data encrypted at rest? Yes. All production data stores are encrypted at rest under AWS KMS. Databases and caches use customer-managed keys that rotate automatically each year. File systems use AWS-managed keys, and object storage uses S3 server-side encryption (AES-256). Key lifecycle management is delegated to AWS KMS, so keys are generated and held in hardware-backed key management and never handled manually. How are secrets managed? Application secrets are held in AWS Secrets Manager. Credentials for your third-party integrations are encrypted with AES-256 in the application, in addition to database encryption at rest. User passwords are never stored by CaptionHub; they are held by Auth0 as salted bcrypt hashes. Authentication and access control How does CaptionHub handle authentication? We use Auth0 to manage authentication, which enables multi-factor authentication, password strength management, and so on. For SSO, we use WorkOS. Custom integration with your own authentication schemes is available for our on-premise customers. What happens if my credentials are leaked in a third-party breach? Via Auth0, CaptionHub protects and notifies users if and when their credentials are leaked by a data breach of a third party. CaptionHub prevents access until the user has reset their password. What access does a new user have by default? None. By default, a new user for CaptionHub has no access – permission needs to be explicit, and given for each and every project. Can you produce an audit trail which logs who has accessed what? By default a user can't see anything in CaptionHub, they have to be manually given access to a project before they can view it. We track user login times and IP address, and we log various forms of activity: handover, download, assignment, etc. Who can see my information? Access to data is limited to a small set of CaptionHub engineering roles under least privilege, with quarterly access reviews. From time to time CaptionHub engages third-party developers. They are contractually bound by confidentiality, work through the same code-review pipeline and have no access to production. Do CaptionHub employees have access to customer data? We operate least privilege: employees receive only the access their role requires. Access to production and customer data is restricted to a small set of engineering roles, and front-line support staff have no customer-data access unless a customer explicitly grants it. Access is reviewed quarterly. What additional security measures are available to Enterprise customers? Enterprise customers can use IP allow-listing, enforced multi-factor authentication, SSO or custom authentication, and watermarking of encoded media. How is content protected from unauthorised downloads and screen captures? Expiring URLs mean that it's difficult to download linked media, even if access is granted, and the logged in user's email address is superimposed over video, making screen captures traceable. Testing and threat detection How often is CaptionHub tested for vulnerabilities? Detectify scans our systems every week using the latest attack vectors. We carry out penetration testing and code review at least annually, and after any major architectural change. Every container image is scanned before deployment. Our security control framework is reviewed annually through the ISO 27001 audit programme. How are containers and infrastructure monitored for threats? All software reaches production through our peer-reviewed CI/CD pipeline. Container images are immutable, scanned with Trivy and AWS Inspector before deployment, and no additional software is installed at runtime. Amazon GuardDuty provides continuous threat detection across our AWS accounts, with CloudTrail and CloudWatch providing the audit and monitoring trail. What malware protection is in place? Our workloads run mostly as unprivileged containers on AWS Fargate, where AWS provisions, hardens, patches and isolates the underlying hosts. The few workloads on EC2 run on hardened images (CIS and DISA STIG) that are replaced rather than patched in place, with no inbound SSH. Detection is cloud-native rather than agent-based, through Amazon GuardDuty. All staff devices are company-managed through MDM, with Bitdefender GravityZone endpoint protection, full-disk encryption and automatic OS updates. Is there a Web Application Firewall? Yes. All requests go through a Web Application Firewall to filter traffic from known malicious IPs or with patterns that look like common attacks. Development practices How is code secured before deployment? Rules for software and system development cover system design, development environments, secure testing and development principles. All code is peer-reviewed through pull requests before deployment, with security analysis an explicit part of review. Static analysis tests every change for security vulnerabilities, and we manage dependency updates continuously, prioritising security patches. Are development and production environments separated? Yes. Development, staging and production environments are separated in distinct AWS accounts. Can developers access running containers? No SSH or password access to running containers is possible. Where a developer needs to connect, this is done through AWS Systems Manager under least-privilege IAM, and is logged. Developers hold no long-lived AWS keys: they sign in through single sign-on with enforced multi-factor authentication and receive temporary credentials. Personnel Are employees screened before joining? Yes. Every hire goes through employment-reference checks before joining and identity and right-to-work verification at onboarding. Enhanced checks, such as criminal-record checks, apply to roles with elevated access. All staff complete a 3-month probation period. Do employees receive security training? All employees complete security-awareness training on joining and on an ongoing basis, including simulated phishing. Are contractors bound by confidentiality agreements? Contractors and third parties are bound by contractual confidentiality obligations or an NDA before they are given access. Core security policies must be read and acknowledged before access to any information system is granted. How is remote working secured? We operate a zero-trust model rather than a VPN. All staff use company-managed devices enrolled in MDM, and multi-factor authentication is required on every system that supports it, with single sign-on wherever available. We maintain clear desk and clear screen policies with appropriate training. What happens when an employee leaves? When someone leaves, access to every system is revoked on or before their last day through a documented checklist, with evidence captured for each system. Personal devices are not used for company work. Continuity and backups How is CaptionHub backed up? Databases have continuous point-in-time recovery over a 35-day window, with daily backup copies replicated to a segregated AWS account with tightly restricted access, so backups survive even the compromise of the production account. Video media is stored on Amazon S3 (99.999999999% durability) and is not separately backed up. Caption and work data is fully restorable from database backups. Is there a single point of failure? No. CaptionHub runs in a high-availability pattern within our primary region: multi-availability-zone databases with automatic failover, and infrastructure-as-code to scale services. For a full regional failure we fail over to our disaster-recovery environment in Frankfurt, with a committed recovery time of 8 hours and a worst-case data loss of 24 hours. Is there a business continuity plan? Yes. We maintain a business continuity and disaster recovery policy and plan. We rehearse disaster recovery annually and test the business continuity plan annually, and review the plan after each test. Incidents and third parties What about incident response and data breaches? CaptionHub runs a documented incident-response process on a dedicated incident-management platform, with defined severity levels, an on-call escalation path and a public status page. Automated alerting routes to the team continuously. We have formal breach-notification procedures, including notifying the regulator within 72 hours where required, and every incident concludes with a documented post-incident review. How do you handle supplier and third-party security? Every supplier is recorded in our supplier register with a criticality and data-access rating, risk-assessed on onboarding and verified annually. For critical vendors this includes reviewing their SOC 2 and ISO attestations. Contracts include security and data-protection clauses. Is my data shared with third parties? Some sub-processors, such as our hosting provider, process data as a core part of delivering the service; they are all listed in our sub-processor register. Optional third-party AI services, such as automatic transcription and machine translation, are used only once you enable them for your team. We hold data-processing agreements with all our processors. How is data disposed of securely? Disposal is formal: managed remote wipe for devices, secure erasure for logical data, and certified destruction for physical media. Timbra (live captioning) How are captions for public live video secured? Captions are served via a publicly visible URL containing a unique, hard to guess identifier for the stream. This identifier can be rotated on request. Can Timbra be locked down to authorised access only? Yes. Timbra projects can be configured to only allow authorised access. In this mode, all public endpoints are disabled, and access to caption output is only possible via the API using valid API credentials. Can Timbra be evaluated privately? Yes. Timbra can be evaluated in private mode, where no data is publicly available. What low-latency input methods are supported? Customers can choose SRT, which has built-in AES encryption, or RTMP, which is unencrypted but secured with an unguessable stream key. How long is caption data retained? All transcription and caption data is kept within the CaptionHub system. Captions are no longer available for archived and deleted projects. For transcription, customers can opt to use a private install of our transcription engine.