Trustpilot 5 stars 4.7 · 3,505 reviews Trustpilot

Your photos, kept safe and private.

Every photo your team uploads is encrypted, deleted 30 days after generation, and never used to train AI models, ours or anyone else's.

No training

Your photos are never used to train AI.

HeadshotPro generates your headshots and stops there.

No model training

Uploaded photos are never used to train, fine-tune, or improve any AI model.

One-shot generation

We generate your headshots from a single session. No personal AI model is built from your face or stored afterward.

Automatic deletion

Uploaded photos are deleted 30 days after your headshots are generated.

You stay the owner

Your photos and headshots are yours. Delete them anytime, and we delete our copies too.

Compliance

Enterprise-grade security at every layer.

HeadshotPro is built with the controls security and procurement teams expect, and the documentation to prove it.

SOC 2 Type II

Independent audit of our security controls. Full report available on request.

Request report
GDPR compliant

Compliant with GDPR, UK GDPR, CCPA, and Singapore PDPA. HeadshotPro acts as your data processor. Your admin remains the data controller.

DPA & SCCs

Sign our Data Processing Agreement. International transfers are covered by EU SCCs (Module Two) and the UK IDTA.

Read the DPA
Subprocessor transparency

Our full list of subprocessors is published and kept current.

View list
PCI-compliant payments

Card payments are handled by Stripe. HeadshotPro never stores full card data.

Breach notification

We notify affected customers without undue delay, within 48 hours of a confirmed personal-data breach and within 72 hours for other security incidents.

Identity

Control who gets in, and how.

Admins get multiple ways to authenticate their team and lock access down to verified company domains.

Single Sign-On (SSO)
Enterprise

Authenticate your team through your identity provider with WorkOS-backed SSO.

See company plans
SAML 2.0 & OAuth

Works with Okta, Microsoft Entra ID, Google Workspace, and most major identity providers.

Domain enforcement

Require SSO for your verified domains and block email/password and social logins.

JIT provisioning

New employees get an account automatically the first time they sign in through SSO.

SCIM provisioning
On request

Provision and deprovision users from your IdP.

MFA enforcement

Require multi-factor authentication for every admin.

Roles & permissions

Assign Admin and Member roles to control who can manage your organization.

SSO audit log

Review SSO authentication events, filterable by user, event type, and date.

Privacy

Designed to protect your team's data.

From upload to deletion, your team's photos stay encrypted, isolated, and under your control.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ (256-bit) and at rest with AES-256.

Automatic photo deletion

Admins can also auto-delete all member data on the same 30-day schedule as uploaded photos.

Data subject rights

Members can access, correct, export, or erase personal data on request. Account deletion removes personal data within 14 days.

Data residency

Your team's photos and headshots are stored in the European Union by default (Western Europe), with encrypted failover to the US for backup and disaster recovery.

Operations

Always monitored, always patched.

HeadshotPro's infrastructure is continuously tested, scanned, and hardened against abuse.

Third-party penetration testing

Independent security firms regularly test HeadshotPro for vulnerabilities.

Continuous monitoring

Sentry monitors application health, errors, and performance continuously, with alerts on anomalies.

Rate limiting

Per-IP and per-account limits protect sensitive endpoints from abuse.

Attack-pattern blocking

We filter suspicious and malicious requests before they reach the app.

Least-privilege production access

Only the staff who need it have production access, and every access is logged.

Backups & disaster recovery

Hourly backups with point-in-time recovery, a 2-hour RTO and 1-hour RPO, and restoration tested at least quarterly.

Running a security review?

Have a security questionnaire or a specific requirement? Send it over and we'll turn it around quickly.