Security
Last updated: October 1, 2026
aisenn holds campaign briefs, unreleased content and approval records — material that is commercially sensitive and, until it is posted, confidential. This page describes how that is handled, and what we have not done yet.
Architecture and hosting
- The application is a Next.js app hosted on Netlify, served over HTTPS only.
- Application data lives in a managed PostgreSQL database on Neon, encrypted at rest and reached over TLS.
- Video is handled by Mux; other files by UploadThing. Both are accessed over TLS and store content encrypted at rest.
- There are no self-managed servers. Administrative database access is limited to the engineering team and used for operations and support, not routine work.
Authentication
- Identity is handled by Clerk. aisenn never receives or stores passwords.
- Social sign-in, multi-factor authentication and session management are Clerk features and are configured at the organization level.
- SAML single sign-on and enforced multi-factor authentication are supported by Clerk and can be enabled on your organization. They are not on by default — if your security policy requires either, say so before onboarding so it is configured from the first sign-in rather than retrofitted.
Access control
Every account belongs to an organization, and every member of an organization holds one of five seats. Capability is derived from the seat, enforced server-side on every request rather than hidden in the interface:
- Owner — full control, including billing and transferring ownership.
- Admin — full control except transferring ownership.
- Manager — runs campaigns and deals day to day.
- Reviewer — reviews and approves deliverables; no campaign or billing control.
- Observer — read-only.
Beyond the seat, access is scoped to the work: a creator on a multi-creator campaign sees their own deliverables and not their peers', and an agency acts on a campaign only where it is formally engaged by the brand or representing the creator. Approvals record who gave them, and where an agency acted on a principal's behalf, that too.
Sharing outside the platform
Campaigns, deals and content can be shared by link so that someone without an account — a CMO, a lawyer — can review. Those links carry a 256-bit random token, are scoped to the one thing they point at, can be set to view-only, and can be revoked or rotated at any time. Video on a share link is streamed from signed, expiring URLs rather than exposed as a file URL; downloading a specific file is a separate, explicit action and is limited to the final approved version. Recap links additionally log each view, so the owner can see when a link is circulating further than intended.
Retention and deletion
- Account deletion — a deletion request starts a 30-day grace period, after which the account and its data are permanently purged by a scheduled job.
- Campaign working material — resources attached to a campaign (reference material, brand assets, B-roll) are deleted 60 days after the campaign ends. Members are warned by email and in-app 7 days ahead, and nothing is deleted until that warning has stood for at least 3 days.
- Archived campaigns — retained according to the plan: 7 days on the free creator plan, 30 days on creator Pro, 90 days on Starter, 12 months on Growth, and indefinitely on Enterprise.
- WhatsApp — where a campaign uses WhatsApp for approvals, message content and phone numbers are erased 90 days after the message. The approval record itself (what was approved, by whom, when) is retained for the campaign's lifetime as part of the audit trail.
- Recap view logs — IP addresses are never stored. A view is recorded against a salted hash so repeat visits can be recognised without retaining the address.
Payments
Subscriptions are billed through Clerk's billing integration, and AI credit packs through Stripe Checkout. Both are hosted by the provider: card details are collected and held by Stripe, and aisenn never receives or stores a card number. Money for creator work itself does not move through aisenn — it is paid outside the platform and recorded against the deal, so we are not a payment intermediary and hold no creator bank details.
AI processing
Some features — contract analysis, brief extraction — send the document you supply to Anthropic for processing. This happens only when you invoke the feature on a specific document, never in the background across your library. Anthropic does not train on data submitted through its API. If your policy prohibits sending contracts to a third-party model, those features can be left unused; nothing else depends on them.
Monitoring and measurement
- Application errors are reported to Sentry.
- API requests are rate limited to 100 per 10 seconds per address, via Upstash.
- Google Analytics is loaded on both the marketing site and the signed-in application, and measures page views and feature usage. It is not given campaign content, contract text, or the contents of your library. If your policy prohibits analytics inside an authenticated application, tell us — it can be scoped to the marketing site for your organization.
- We do not sell data and we run no advertising or ad-retargeting scripts.
Certification status
Stated plainly, because a security questionnaire that catches one overstatement is right to discard the rest:
- aisenn does not currently hold a SOC 2 Type II report or ISO 27001 certification.
- Our infrastructure providers — Netlify, Neon, Clerk, Mux, Stripe, Anthropic — maintain their own SOC 2 and equivalent attestations, and their reports are available from them directly.
- We will complete a security questionnaire, sign an NDA, and talk to your security team directly. If a formal attestation is a hard requirement for your procurement process, tell us and we will tell you honestly where we are rather than wasting your evaluation cycle.
Reporting a vulnerability
Email support@aisenn.app with enough detail to reproduce the issue. We will acknowledge within two business days. Please do not run automated scanning against production or access data belonging to anyone but yourself while testing.
Data processing terms
Our processor terms and the full list of subprocessors are at aisenn.app/dpa. See also our Privacy Policy and Terms of Service.