Skip to main content
A short summary; full details in our privacy policy.

The basics

Tenant isolation

Strict separation between customers. Customer A’s transcripts never appear in Customer B’s prompts. Enforced at the database level (Postgres row-level security) and verified pre-launch.

Encryption

All data encrypted in transit (TLS) and at rest (Postgres + Cloudflare R2).

No fine-tuning of customer data

TrailerCast doesn’t fine-tune AI models on your data. We use foundation models from Anthropic; your data is input on a per-request basis under enterprise DPAs.

Audit logs

Every AI inference is logged with what was retrieved + who triggered it. 90-day retention, then auto-purged.

Account security (added August 2026)

Two-factor authentication

TOTP-based 2FA with backup codes. Set it up under your avatar → Password & security. Works for password and Google sign-ins.

Company-wide 2FA requirement

Admins can require 2FA for the whole workspace (Security & Permissions). Teammates without it are walked through enrollment at their next sign-in and can’t use the app until enrolled.

Sign out everywhere

Lost a laptop or used a shared machine? One click under Password & security revokes every session on every device within a minute.

Expiring media links

Recording and trailer playback runs on short-lived signed URLs. A copied media URL stops working after it expires; sharing is done through share links you control, not raw file URLs.

AI providers + data handling

Data deletion

Private recordings

Global Admin can mark any recording as private. Private recordings are invisible to:
  • Other teammates (Members and Admins, including Admins with normally elevated permissions)
  • The Library
  • Universal search results
  • Any team-level reports
The owner (whoever’s account the recording is on) and the Global Admin always see private recordings. This is the right surface for HR conversations, legal calls, internal strategy meetings, anything sensitive that shouldn’t be team-visible by default.

What we capture vs what we don’t

We capture:
  • The recording you uploaded or that the bot pulled in
  • The transcript we generated
  • AI-generated outputs (summary, moments, deal brief)
  • Engagement on share pages (views, watch %, heat-map)
  • Comments, conversations, and team activity
We don’t capture:
  • Other tabs in your browser
  • Your screen content outside of recordings you explicitly upload or schedule a bot for
  • Your email content or calendar event bodies (for calendar integrations, we read titles and attendees only)
  • Any data from other TrailerCast customers, strict tenant isolation

Compliance posture

Subprocessor list

We list every subprocessor on our privacy page. Major ones:
  • Anthropic (AI reasoning)
  • Deepgram (transcription)
  • ElevenLabs (voice synthesis)
  • Recall.ai (calendar meeting bots)
  • Cloudflare R2 (object storage for recordings + trailers)
  • Railway (compute)
  • Vercel (frontend hosting)
  • Stripe (billing)
  • Postmark (transactional email)
  • Plausible (analytics, cookieless)
  • Microsoft Clarity (analytics, cookie-gated)
We give 30 days’ notice before adding a new subprocessor.

Data exports

You can export:
  • Any individual demo’s transcript + AI outputs (settings menu on the demo)
  • Bulk demo metadata via the Pro+ API (coming Q3 2026)
  • Audit log via support email request

Security incident response

If we discover a security incident affecting your account, we’ll notify you within 72 hours of confirmation, with:
  • Description of the incident
  • Affected data scope
  • Mitigation steps taken
  • Recommendation for your action (rotate API keys, audit user activity, etc.)
Our incident response runbook is available to enterprise customers under NDA.

Reporting a vulnerability

Found something? Email security@trailercast.io. We respond within 24 hours and don’t take legal action against good-faith researchers. For the full responsible-disclosure policy, see trailercast.io/security.