How client material is protected

Effective date: 18 September 2026
Security reports: productions@lowlightking.com

A production company holds unreleased brand assets, scripts under embargo, executives on camera, and the personal data of everyone who appeared on the shoot. This page states what protects that material. It states the controls that exist, and it does not claim any that do not.

1) What we do not claim

We hold no ISO/IEC 27001 certification, no SOC 2 report, and no third-party security audit. Where a client's procurement process requires one, we will say so rather than let a questionnaire imply otherwise. Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 treats certification as one route to demonstrating reasonable security practices; the route we take is the documented programme described below.

No security programme guarantees zero risk, and this one makes no such claim.

2) Access

  • Two-factor authentication is enabled on the accounts that hold client material: our Cloudflare account, Microsoft 365, and the CRM.
  • Access is granted per project and per person. Crew and contractors get access to the project they are working on, and not to the archive.
  • Review and delivery links are issued per project and may be revoked, including for non-payment under clause 4.5 of the Terms.
  • Access and download activity on delivery platforms is logged.

3) Storage and devices

  • The machines that hold footage run full-disk encryption. A lost or stolen laptop is a lost device, not a disclosed archive.
  • Masters and deliverables are held in Cloudflare R2. Data in transit to and from it is encrypted by the platform, and objects are encrypted at rest by the platform.
  • Material is deleted on the schedule published in the retention policy, which is itself a security control: footage that has been deleted cannot be leaked. Written confirmation of a deletion is issued on request.
  • Backups are restorable, and a deletion reaches them on the backup's own cycle rather than immediately. A backup copy is not used for anything in the meantime.

4) People

Freelance crew and contractors sign written non-disclosure agreements as a condition of engagement, and those obligations survive the project. Scripts, sets, call sheets, shot lists and captured media are confidential unless the client has released them. Unauthorised recording on a set is grounds for removal from it.

Access is granted at the start of an engagement and removed at the end of it, per person and per project. We check identity and the right to work for anyone we pay, because tax and companies law require it; we do not run criminal-record or credit checks, and where a client's own vetting standard requires one we say so rather than let a questionnaire imply we do.

Client material never trains a model. Nothing a client gives us, and nothing we shoot for them, is used to train, fine-tune, evaluate or improve a machine-learning model. The AI and synthetic media policy states the rule and clause 13 of the data processing agreement makes it enforceable.

5) Processors

The third parties that hold client or personal data on our behalf are listed below and in the data processing agreement, which is where the contractual security commitments sit.

  • Cloudflare, Inc. — Website hosting and delivery, storage of production masters and deliverables, and cookieless traffic measurement.
  • Microsoft Corporation — Business email and document storage.
  • Vidyard — Hosting for the audit video we make for you, and the viewer-level view data shown back to you on the audit call. It is not embedded on this website.
  • HubSpot, Inc. — The form used across the site to request the Video Strategy Audit, and the record of what is submitted through it.
  • PostHog, Inc. — Product analytics for this website: which pages are read, in what order, and what is clicked on them. It is not cookieless — it sets a browser identifier of its own, which is the first storage this site places of its own accord. It also records the screen during a visit and replays it back to us, collects script errors, and can show a chat window, a survey or a guided tooltip.
  • Vimeo, Inc. (named, not yet carrying data) — The video player on this site, which loads only when a visitor presses play and is asked not to track. No video identifier is configured yet, so nothing has ever loaded.
  • Freshworks (Freshsales) (named, not yet carrying data) — The record of enquiries made through this website, and the sales correspondence that follows one.

We are not liable for a breach of a third-party platform beyond our reasonable control, which clause 12.3 of the Terms also states. What we control is which platforms hold what, and that list is published rather than kept internal.

Notice of a change. Clause 6 of the DPA commits us to 30 days' notice before a processor is added or replaced. To be on the list for that, write to productions@lowlightking.com with “Subprocessor notice” in the subject line and the address to use. The list is used for nothing else.

5A) Answering your security review

  • A security questionnaire is answered within 30 days of receiving it, in writing, under clause 10 of the DPA. We answer it ourselves; we do not have a certification to point at instead.
  • An on-site audit is available once in any twelve-month period on 30 days' notice, on the terms in that clause.
  • A countersigned DPA is issued on request, including on your own paper where we can sign it.
  • Supplier security addenda — including requirements flowing down from the NIS 2 Directive, DORA or a parent company's global standard — are read and answered clause by clause. We will tell you which we can meet and which we cannot, before signing, rather than signing and hoping.
  • What we will not do is answer a questionnaire in a way that implies a control we do not operate. Section 1 is the list of things we do not have, and it does not get quieter in a spreadsheet.

6) Incidents

If we become aware of a personal data breach we investigate it immediately, contain it, and tell the people and organisations affected. Where the law requires an incident to be reported — to the Data Protection Board of India under the Digital Personal Data Protection Act 2023 and the Rules made under it, or to CERT-In under its directions of 28 April 2022 where those apply to us — we report it within the time that rule sets. Clients are told about an incident affecting their material whether or not a regulator has to be.

7) Reporting a vulnerability

If you believe you have found a security problem in this website or in how we handle data, write to productions@lowlightking.com with “Security” in the subject line, and describe what you found and how to reproduce it. We acknowledge within 24 hours and aim to resolve within 30 days, which is the same commitment the grievance mechanism in the privacy notice makes.

A machine-readable version of this section is published at /.well-known/security.txt, in the format RFC 9116 sets.

In scope: this website and the Worker that serves it.

Out of scope: the third-party platforms listed above, which have their own disclosure programmes; social engineering of our staff, crew or clients; anything requiring physical access; and denial-of-service testing.

What we ask. Test only against your own data. Do not access, modify or download anyone else's. Do not degrade the service for other people. Give us a reasonable opportunity to fix the problem before you describe it publicly.

What we commit to. We will not pursue legal action over research conducted in good faith within those limits, and we will credit you if you want the credit. We do not run a paid bug bounty and no payment should be expected.

The other documents

This is one of nine. The index lists them all and says what each one decides.