Skip to main content

Security & Compliance

How VidScore™ protects your data.

How We Think About Security

Security is a design constraint, not a feature we add later.

Fail Closed, Not Open

When any signal is missing, ambiguous, or degraded, our system defaults to restrictive behavior. Content is never promoted or processed unless explicitly verified safe.

Platform Reliance

VidScore does not host video content. We rely on YouTube's infrastructure for delivery and their enforcement mechanisms for content moderation. We continuously recheck video availability and restrictions.

Minimal Data Collection

We store only what's necessary: video metadata, analysis outputs, and safety verdicts. No raw video files, no user browsing history, no personally identifiable information beyond what's required for account management.

Automated Safety

All content safety decisions are automated, deterministic, and auditable. Our four-tier verdict system (Allow, Sensitive Allow, Restrict, Block) ensures consistent handling across all content.

Security Controls

Multiple independent layers. A failure in one doesn't compromise the rest.

Infrastructure Protection

  • ·DDoS protection and web application firewall
  • ·Edge rate limiting and bot detection
  • ·IP-based throttling for abuse prevention
  • ·Geographic distribution via CDN

Authentication & Access

  • ·Token-based authentication with email verification
  • ·Multi-factor authentication support
  • ·Row-level security enforced at the database layer
  • ·Separated read and write access credentials

Data Protection

  • ·Encryption at rest for all stored data
  • ·TLS 1.3 for all data in transit
  • ·Regular credential rotation
  • ·Payments handled by PCI-compliant processor, no card data stored

Content Safety

  • ·Automated content classification pipeline
  • ·Topic and intent analysis, not just keyword matching
  • ·Continuous YouTube availability rechecks
  • ·Instant degradation on policy enforcement changes

Input Validation

  • ·Strict format validation on all inputs
  • ·Parameterized queries only, no dynamic SQL
  • ·Output sanitization for all external text
  • ·Content Security Policy headers

Monitoring & Response

  • ·Real-time anomaly detection
  • ·Automated abuse response escalation
  • ·Global kill switches for emergency response
  • ·Append-only audit logs with retention

Compliance Posture

We maintain documented controls and internal governance appropriate for our scale. We are not yet SOC 2 certified; we will pursue that as enterprise demand grows.

What we maintain

  • Documented content safety policy
  • Trust & Safety architecture documentation
  • Safety decision audit logs with retention
  • Blocklist records with reason tracking
  • Minimal user data footprint
  • Privacy Policy covering GDPR and CCPA

Our commitments

  • We do not knowingly host illegal content
  • We respond promptly to platform enforcement changes
  • We support lawful takedown and preservation requests
  • Transparency about our analysis methodology
  • Material data practices disclosed in our Privacy Policy
Security questionnaires, architecture reviews, and custom documentation available for enterprise engagements on request.

Responsible Disclosure

If you discover a security vulnerability in VidScore, please report it to us before making it public. We take all reports seriously and will respond promptly.

Email: [email protected]

  • Include a description of the vulnerability and steps to reproduce
  • We will acknowledge receipt within 2 business days
  • Give us reasonable time to remediate before public disclosure
  • We do not take legal action against good-faith security researchers

Security Questions?

We can walk through our architecture, provide documentation, or fill out security questionnaires.

Last updated: February 2026  ·  How We Score  ·  Enterprise Data  ·  B2B Terms