Trust

Security at Rezeis

We run media infrastructure for other people's products. That only works if the boring parts — access, isolation, encryption, disclosure — are handled properly.

Encryption in transit & at rest

TLS 1.2+ on every endpoint. Stored media and metadata are encrypted at rest with AES-256.

Scoped API keys

Keys are per-project and can be restricted to read-only. Rotate or revoke instantly from the dashboard.

Tenant isolation

Each project's media and manifests are namespaced and access-checked on every request path.

Signed delivery

Private content is served only against short-lived tokens with optional IP and geo pinning.

Least privilege

Internal access to production is role-gated, logged, and reviewed. Human access to customer media is off by default.

Auditable webhooks

Every webhook is signed with HMAC-SHA256 so you can verify authenticity before acting.

Reporting a vulnerability

If you believe you've found a security issue, email security@rezeis.click. Include steps to reproduce and any relevant request IDs. We acknowledge reports within one business day and will keep you updated through resolution. We do not pursue researchers acting in good faith.

Please don't run automated scanners against the production API without arranging a window with us first — it competes with real customer traffic and triggers our abuse controls.

Compliance

A SOC 2 Type II report and our current sub-processor list are available under NDA to customers on the Scale plan. Contact hello@rezeis.click.