Security at Rezeis
We run media infrastructure for other people's products. That only works if the boring parts — access, isolation, encryption, disclosure — are handled properly.
Encryption in transit & at rest
TLS 1.2+ on every endpoint. Stored media and metadata are encrypted at rest with AES-256.
Scoped API keys
Keys are per-project and can be restricted to read-only. Rotate or revoke instantly from the dashboard.
Tenant isolation
Each project's media and manifests are namespaced and access-checked on every request path.
Signed delivery
Private content is served only against short-lived tokens with optional IP and geo pinning.
Least privilege
Internal access to production is role-gated, logged, and reviewed. Human access to customer media is off by default.
Auditable webhooks
Every webhook is signed with HMAC-SHA256 so you can verify authenticity before acting.
Reporting a vulnerability
If you believe you've found a security issue, email security@rezeis.click. Include steps to reproduce and any relevant request IDs. We acknowledge reports within one business day and will keep you updated through resolution. We do not pursue researchers acting in good faith.
Please don't run automated scanners against the production API without arranging a window with us first — it competes with real customer traffic and triggers our abuse controls.
Compliance
A SOC 2 Type II report and our current sub-processor list are available under NDA to customers on the Scale plan. Contact hello@rezeis.click.