Every photo your team uploads is encrypted, deleted 30 days after generation, and never used to train AI models, ours or anyone else's.
HeadshotPro generates your headshots and stops there.
Uploaded photos are never used to train, fine-tune, or improve any AI model.
We generate your headshots from a single session. No personal AI model is built from your face or stored afterward.
Uploaded photos are deleted 30 days after your headshots are generated.
Your photos and headshots are yours. Delete them anytime, and we delete our copies too.
HeadshotPro is built with the controls security and procurement teams expect, and the documentation to prove it.
Independent audit of our security controls. Full report available on request.
Request reportCompliant with GDPR, UK GDPR, CCPA, and Singapore PDPA. HeadshotPro acts as your data processor. Your admin remains the data controller.
Sign our Data Processing Agreement. International transfers are covered by EU SCCs (Module Two) and the UK IDTA.
Read the DPACard payments are handled by Stripe. HeadshotPro never stores full card data.
We notify affected customers without undue delay, within 48 hours of a confirmed personal-data breach and within 72 hours for other security incidents.
Admins get multiple ways to authenticate their team and lock access down to verified company domains.
Authenticate your team through your identity provider with WorkOS-backed SSO.
See company plansWorks with Okta, Microsoft Entra ID, Google Workspace, and most major identity providers.
Require SSO for your verified domains and block email/password and social logins.
New employees get an account automatically the first time they sign in through SSO.
Provision and deprovision users from your IdP.
Require multi-factor authentication for every admin.
Assign Admin and Member roles to control who can manage your organization.
Review SSO authentication events, filterable by user, event type, and date.
From upload to deletion, your team's photos stay encrypted, isolated, and under your control.
Data is encrypted in transit with TLS 1.2+ (256-bit) and at rest with AES-256.
Admins can also auto-delete all member data on the same 30-day schedule as uploaded photos.
Members can access, correct, export, or erase personal data on request. Account deletion removes personal data within 14 days.
Your team's photos and headshots are stored in the European Union by default (Western Europe), with encrypted failover to the US for backup and disaster recovery.
HeadshotPro's infrastructure is continuously tested, scanned, and hardened against abuse.
Independent security firms regularly test HeadshotPro for vulnerabilities.
Sentry monitors application health, errors, and performance continuously, with alerts on anomalies.
Per-IP and per-account limits protect sensitive endpoints from abuse.
We filter suspicious and malicious requests before they reach the app.
Only the staff who need it have production access, and every access is logged.
Hourly backups with point-in-time recovery, a 2-hour RTO and 1-hour RPO, and restoration tested at least quarterly.
Hand these to your IT, legal, and procurement teams. Reports and summaries are self-serve through our Trust Center, no NDA required.
Have a security questionnaire or a specific requirement? Send it over and we'll turn it around quickly.