Security and Trust
Your work and your data, kept safe.
Security is part of how the product is built, not an afterthought. This page explains, in plain language, how we protect your account, your payments, and the files you trust us with.
Last updated 18 August 2026
Encryption in transit and at rest
Every connection to our website and our API runs over HTTPS. Your uploads, your account details, and everything in between travel over an encrypted channel.
We also enforce HSTS (HTTP Strict Transport Security) on both the site and the API, so browsers are told to only ever connect over a secure connection.
The files you upload and the subtitles we generate are also encrypted at rest, using AES-256.
Accounts and passwords
Passwords are never stored as plain text. We hash them with Argon2, a modern algorithm built specifically to resist password cracking.
You can also sign in with Google instead of a password. Sign-in and registration are rate limited, so an attacker cannot try thousands of passwords in a row.
Payments
Payments are handled by an external, PCI-DSS compliant payment provider.
Your card details go straight to them and are never sent to or stored on our servers. We only keep a reference to the transaction, never the card number.
Where your data lives
Our platform runs entirely in the European Union, in Paris.
- Your uploaded media and the files we generate from it are stored in Paris.
- Your account data is stored in a managed database in Paris, backed up automatically every day.
Your data and deletion
We store the media you upload and the subtitles and transcripts we generate from it, so you can come back and download or edit your work.
You stay in control. You can delete your own media at any time from your My Videos page, and deletion is permanent: the video, the subtitles and any burned-in copy are erased from our storage, with nothing kept in reserve that would let us recover them.
If you would like your account and all associated data removed, contact us and we will take care of it.
For full details on what we collect and how we use it, see our privacy statement.
Application hardening
Beyond encryption, we apply a number of standard protections across the platform:
- Security response headers on every page we serve.
- A scoped CORS policy that only allows our own applications to call the API, rather than any website.
- A database that is never exposed to the public internet. It can only be reached from inside our private network.
Enterprise and compliance
For enterprise engagements we are happy to support your review process. We can complete a security questionnaire, walk you through how the platform is built, and arrange a penetration test on request.
We do not make compliance claims we cannot back up. If your organization requires a formal certification such as SOC 2 or ISO 27001, get in touch and we will discuss your requirements.
Reporting a security issue
If you believe you have found a security vulnerability, we want to hear from you. Email security@subtitling.net with the details and we will look into it. We ask that you give us a reasonable amount of time to respond before sharing it publicly.
We will not pursue legal action against anyone who reports an issue in good faith, as long as you avoid privacy violations and do not disrupt the service for others.
You can also find our security contact at /.well-known/security.txt.
Rua D. Afonso Henriques 132
4950-854 Cortes, Portugal
VAT / NIPC 518326918