Last updated: June 24, 2026
This overview summarizes how HeadshotPro protects your team's data. It's written for IT, security, and procurement teams running a vendor review. For the underlying documents, see Documentation for your security review at the end.
At a glance
| Area | Summary |
|---|
| Certification | SOC 2 Type II (Security); report available on request |
| Compliance | GDPR, UK GDPR, CCPA, Singapore PDPA |
| AI training | Your photos are never used to train AI models, no exceptions |
| Data at rest | Stored in the EU (Cloudflare, Western Europe); encrypted US failover for backup |
| Encryption | TLS 1.2+ in transit, AES-256 at rest |
| Photo retention | Input photos auto-deleted 30 days after generation |
| Account deletion | Personal data erased within 14 days of request |
| Identity | SAML 2.0 / OAuth SSO, JIT provisioning, admin MFA |
| Availability | 99.9% uptime target; RTO 2h / RPO 1h |
| Incident response | Breach notification within 48–72 hours |
Certifications and compliance
- SOC 2 Type II for the Security Trust Services Criteria, examined by an independent auditor. The full report can be requested via our Trust Center.
- Compliant with GDPR, UK GDPR, CCPA, and Singapore PDPA. HeadshotPro acts as the data processor; your organization remains the data controller.
- A Data Processing Agreement is publicly available and applies automatically to all customers. International transfers are covered by the EU Standard Contractual Clauses (Module Two) and the UK IDTA.
- Independent penetration testing is conducted regularly, alongside continuous automated security scanning on a 24-hour cycle (dependency vulnerabilities, file integrity, and suspicious-request patterns).
Your photos are never used to train AI
Uploaded photos and generated headshots are never used to train, fine-tune, or otherwise improve any AI model, ours or any third party's. This is an absolute commitment with no exceptions. Customer content is processed only to generate your headshots and to operate, secure, and support the service.
Data storage and residency
- Primary storage for uploaded photos and generated headshots is in the European Economic Area (Western Europe).
- Failover storage is replicated in encrypted form to the United States (GCS, us-east-1) for backup and disaster recovery only.
- Application servers run in the United States (US-West).
- Production databases are managed (MongoDB Atlas), are not exposed to the public internet, and sit behind deny-by-default firewall rules.
- Customer-selectable or contractually pinned data residency is not currently offered.
International data transfers
Where personal data is transferred out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is covered by an approved safeguard under Article 46 GDPR. These mechanisms are incorporated into our Data Processing Agreement (Section 6) and apply automatically to every customer — there is nothing to sign separately.
- EU / EEA: The EU Standard Contractual Clauses, Module Two (Controller to Processor) from Commission Implementing Decision (EU) 2021/914 are incorporated by reference. The SCC Annexes (parties, description of transfer, technical and organisational measures, sub-processors) are completed by the corresponding Annexes of the DPA. Clause 17 Option 1 applies, governed by the laws of Ireland; the competent supervisory authority is the Data Protection Commission of Ireland.
- United Kingdom: The International Data Transfer Addendum (Version B1.0) to the EU SCCs, issued by the UK Information Commissioner, applies — with its tables completed by reference to the EU SCCs and the DPA Annexes.
- Switzerland: The EU SCCs apply with the modifications required under the Swiss Federal Act on Data Protection (FADP), including reference to the Swiss FDPIC and protection for data of legal entities.
- Data importer: Headshot Pro Photography Pte. Ltd. (Singapore). Our EU representative under Article 27 GDPR is iuro Rechtsanwälte GmbH t/a Prighter (Vienna, Austria).
Encryption
- In transit: TLS 1.2 or higher (256-bit). HTTPS only, with no unencrypted channels.
- At rest: AES-256 across account data, uploaded photos, and generated headshots.
- Encryption keys are managed at the infrastructure-provider layer; staff cannot access raw encryption keys.
Retention and deletion
- Input photos are automatically deleted 30 days after your headshots are generated. Earlier deletion is available on request.
- Account deletion triggers full erasure of personal data within 14 days of confirmation.
- Backups are taken hourly with point-in-time recovery, retained for up to one year, then securely deleted.
- Generated headshots are exportable at any time, including within 30 days of account termination.
For full details, see the Data Management & Retention policy.
Identity and access
- Single Sign-On (enterprise): SAML 2.0 and OAuth via major identity providers (Okta, Microsoft Entra ID, Google Workspace), with enforced SSO and just-in-time provisioning.
- Multi-factor authentication: email-based MFA for organization administrators, enforceable across the whole organization. Admins re-verify with a one-time code every 24 hours.
- Authentication: every API request is authenticated and scoped to the signed-in user, so users access only their own records.
- Least-privilege access: production access is role-based, requires approval, is logged with MFA enforced, and is reviewed at least annually. Developers work against staging data, not production customer data.
- Rate limiting is enforced per IP and per account to protect against brute-force and abuse.
Infrastructure and monitoring
- HeadshotPro runs entirely on managed cloud infrastructure (Render, Cloudflare, Google Cloud, Vercel) and operates no facilities of its own. Physical and environmental controls are inherited from these providers' certified data centers.
- Customer data is logically isolated per account on multi-tenant infrastructure.
- Application health and errors are monitored continuously via Sentry. Production console access and security-relevant events are logged and reviewed for anomalous activity.
- Changes follow secure-SDLC practices, including code review and dependency scanning.
Availability and disaster recovery
- Uptime target: 99.9% monthly, with service credits available if missed.
- Recovery objectives: RTO of 2 hours and RPO of 1 hour, supported by hourly backups with point-in-time recovery.
- Regional separation: primary storage (EU) and failover storage (US) are in separate regions.
- Restoration tests are performed at least quarterly.
Incident response
HeadshotPro maintains a documented incident-response and breach-notification process. We notify affected customers without undue delay, and in any event within 48 hours of confirming a personal-data breach and within 72 hours for other security incidents affecting customer personal data. Notice includes the nature of the incident, the categories of data affected, and the remediation taken or proposed, with cooperation and updates as the investigation progresses.
Sub-processors
HeadshotPro publishes and maintains a current list of all sub-processors with access to customer content, including the function each performs and its country. See the Sub-processors page for the live list and our process for notifying customers of changes.
Documentation for your security review
Running a security review or have a questionnaire to complete? Email support@headshotpro.com and we'll turn it around quickly.