GLX Studio operates with the same security posture as the systems it integrates into. SOC 2 Type II. AES-256 encryption at rest. TLS 1.3 in transit. SSO via SAML and OIDC. GDPR-aligned data handling. Optional EU data residency.
Independently audited. Reports available under NDA.
All customer data and assets encrypted with AES-256.
All API and dashboard traffic over TLS 1.3 with HSTS.
Data subject rights, export, and deletion supported.
Brand assets, source decks, contact lists, and rendered video are owned by you. We process them under a Data Processing Agreement, never train models on customer content, and provide export and deletion on demand.
We maintain a public list of subprocessors. Notification of any addition or change is provided in advance per our DPA. Critical subprocessors include AWS, ElevenLabs (voice), and Storyblocks (licensed B-roll).
Data subject rights, export, deletion, breach notification.
Available on Enterprise plans. BAA available on request.
SOC 2 Type II in place. SOC 3 summary available publicly.
US default. EU residency optional on Enterprise.
Reports are available under NDA. Send a note to security and we'll route the docs and a security engineer if you have questions.