ClearFrame

Security

Security across upload, processing, and delivery.

ClearFrame applies layered controls to accounts, projects, media, workers, administrative actions, and completed outputs without claiming certifications the product has not obtained.

Last updated July 21, 2026

ClearFrame SecurityJuly 21, 2026
11. Transport and secrets
22. Account security
33. Media storage and delivery
44. Processing isolation
On this page

1. Transport and secrets

Production traffic should use HTTPS. Application secrets, payment credentials, token keys, and storage credentials stay in protected environment configuration and are not exposed in the frontend.

2. Account security

Passwords are hashed, access and refresh tokens expire, account status is checked, and sensitive routes require authenticated ownership or administrative permissions.

3. Media storage and delivery

Media uses private storage paths, validated filenames, MIME and container checks, authenticated project access, and temporary signed download links.

4. Processing isolation

Queued jobs use explicit task states, dedicated processing paths, timeouts, retries, and controlled FFmpeg argument lists. User filenames are never concatenated into shell commands.

5. Role-based administration

Administrative routes verify permissions server-side. Sensitive support, billing, compliance, retention, and secret operations are separated by role.

6. Audit and monitoring

Important administrative actions, credit transactions, authorization confirmations, project state changes, and compliance operations are designed to leave traceable records.

7. Automatic cleanup

Originals, previews, failures, and outputs follow configured retention windows. Legal holds and compliance restrictions can pause normal cleanup when required.

8. Responsible disclosure

Use the Security report category on the Contact page. Share clear reproduction steps, avoid unnecessary personal data, and do not access or modify another user's content.

9. Certifications

ClearFrame does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, or another external certification on this page.

Next step

Found a vulnerability?

Use responsible disclosure and avoid attaching sensitive footage to the first message.

Report a security issue