Security Practices

Last updated: June 3, 2026

This page describes the technical and organizational measures VideoScripter Kft. maintains to protect the security, confidentiality, integrity and availability of customer data in the Tutorial AI service (Article 32 GDPR). It is referenced by our Data Processing Agreement and may be updated from time to time, provided the overall level of protection is not materially reduced. The Service runs on Google Cloud Platform managed services (serverless Cloud Run, Cloud SQL for PostgreSQL, Google Cloud Storage).

  • Data location. Customer data is processed and stored exclusively within the EEA: primary region europe-west1 (Belgium), disaster-recovery region europe-west4 (Netherlands); Cloud SQL backups in EU multi-region. Data does not leave the EU.
  • Encryption. In transit: HTTPS/TLS 1.2 or higher externally (TLS 1.0/1.1 and SSL disabled, restricted cipher suites, HSTS on all endpoints), TLS 1.3 between internal components, enforced SSL/TLS for the database. At rest: AES-256 (Google Cloud Storage and Cloud SQL). Passwords hashed with Argon2id.
  • Key management. Storage encryption uses Google-managed keys; application secrets and CDN signing keys are held in Google Secret Manager (versioned, immutable, all access audited).
  • Access control. Role-based access within the application (Super Admin, Organization Admin, Workspace Admin, Member, Guest); organization-level mandatory two-factor authentication; Google Workspace SSO supported. Production access is limited to the CTO and two senior engineers using mandatory phishing-resistant 2FA (hardware key, passkey or authenticator app; SMS/e-mail second factors disabled) via dedicated “production-only” privileged accounts re-authenticated every 16 hours; all access is recorded in Google Audit Log. No contractors have production access. Support impersonation occurs only with customer approval and full logging.
  • Data minimization. Only 400×200-pixel click-region still images and sentence-level narration text are sent to AI sub-processors; the full video never leaves the platform. Domain names and e-mail addresses (and optional customer keywords) are automatically anonymized before transmission. No keystrokes, typed text or clipboard content are captured.
  • Availability & resilience. Multi-zone Cloud Run; Cloud SQL high-availability warm failover; dual-region media storage. Daily backups to an isolated backup GCP project (files at 03:00 CET with 30-day recoverability of deleted files and prior versions; database daily full backup with 30-day retention and point-in-time recovery to 1-second granularity for 7 days). RTO and RPO of 24 hours. A documented recovery runbook (restore database and media, redeploy services, restore secrets, validate functionality, logging and access) is tested at least annually (most recent test 2025-06-08).
  • Network & application security. Google Cloud Armor WAF (OWASP Core Rule Set, rate-based bans, scanner detection, reCAPTCHA Enterprise) and Google Cloud Load Balancer/CDN with built-in DDoS protection and SSL termination; a single external ingress point. Database on private IP only. Each environment (production, staging, QA, test) runs in a separate GCP project with its own VPC, firewall and credentials.
  • Vulnerability & patch management. Artifact Registry vulnerability analysis on every image push with 90-day re-scanning; per-build dependency audit, license check, secret scanning and SAST. Remediation targets: Critical (CVSS 9.0–10.0) 48 hours, High 1 week, Medium 4 weeks, Low in the normal development cycle. Container base-image security updates apply automatically with zero downtime.
  • Secure development & change management. Pull-request–based workflow; direct commits to the production branch are prohibited; mandatory reviewer approval; AI-assisted security and privacy review; automated unit/integration/E2E tests plus mandatory manual security testing for security-sensitive changes; immutable Cloud Run revisions with instant rollback.
  • Logging & monitoring. Application activity log (login/logout, failed logins, password changes, project create/open/modify/delete — who, where, what, when) retained for 1 year; Google Cloud audit logs retained 400 days; other operational logs 30 days. Continuous monitoring and alerting via Google Cloud Monitoring/Logging/Error Reporting (e-mail and Slack), with incident handling in incidents.io.
  • Certifications. ISO/IEC 27001 certification is in progress (expected approximately December 2026). [Update this statement upon certification; do not assert certification before it is granted.]

This document is a working draft prepared for review. It is not published until reviewed, dated and approved by VideoScripter Kft.