Our Approach
This page is maintained by the Cinexa team and describes app-visible controls and current practices. It is not a certification and does not constitute legal or compliance advice. Security is a shared responsibility between the Cinexa platform, Cinexa studio owners, and end users.
Secure AI Workflow
Every AI job runs through an execution engine with credit checks, approval gates, error classification and explicit retry controls. Rejected jobs are never re-run automatically and approved outputs are never overwritten.
Private Projects
Projects are scoped to your studio. Access is enforced by row-level security policies on the managed backend so that only invited members of a studio can read or modify its projects, scenes, shots and outputs.
API Key Protection
Third-party AI provider API keys are stored server-side and used only to fulfill your generation requests. Keys are never exposed in client bundles, shared review packages or activity logs.
Studio Data Isolation
Each studio's data — stories, characters, locations, scenes, shots, storyboards and outputs — is isolated by studio identity. Cross-studio access requires an explicit invitation accepted by the receiving studio.
Client Review Privacy
Client review packages share only the items you select. Internal notes, AI provider settings, credit usage and hidden prompts are never visible to clients. Approvals and change requests are tied back to the original scene, shot or output.
Credit Control
Before any expensive generation, Cinexa surfaces a cost preview with Safe → Very High warning levels. You decide whether to proceed, edit the prompt, change provider or cancel.
Platform and Hosting
Cinexa runs on a managed cloud backend with authenticated access and row-level security policies on every user-facing table. Authentication tokens are validated server-side on each request.
Vulnerability Reporting
If you believe you have discovered a security issue, please report it through the Contact page so we can investigate promptly. Please do not publicly disclose details before we have had an opportunity to respond.
Compliance
Cinexa does not currently advertise any third-party certifications such as SOC 2, ISO 27001, HIPAA or PCI-DSS. Any future compliance claims will be added here only when independently verified.