Security and Compliance

We support our customers’ compliance with privacy laws, including GDPR, CCPA and HIPAA, and offer a Data Processing Addendum and Business Associate Agreement. Idomoo’s platform has been evaluated by an independent third-party auditor to confirm that our controls align with industry standards for security and confidentiality.

Our Accreditations

ISO 27001 badge

ISO 27001

Information Security Management Systems

ISO 27799 badge

ISO 27799

Health Informatics – Information Security Management in Health

ISO 42001

Artificial Intelligence Management System

SOC 2 Type 2 badge

SOC 2 Type 2

System and Organization Controls 2 Type 2 compliance

GDPR

EU General Data Protection Regulation

HIPAA

Health Insurance Portability and Accountability Act

CCPA

California Consumer Privacy Act

Cyber Essentials

U.K. government-backed security credential

Need More?

Access certificates, audit reports and security documentation in the Idomoo Trust Center.

Our Security Practices

ISO 27001 – Certified Information Security Management Systems

Idomoo is certified to ISO 27001, the international standard for information security management. This certification is awarded by an accredited third-party body and confirms that we operate a structured, risk-based approach to protecting information assets. Our certification covers policies, technical and organizational controls and full documentation of security procedures.

Audits are conducted periodically to verify continuous compliance with the standard’s requirements. ISO 27001 certification means our customers can trust that Idomoo operates a secure, reliable, and consistent security environment.

Maximum Data Protection

Data security begins at the encryption layer and continues through every stage of its lifecycle, from active transmission to storage within our secure cloud infrastructure.

All communication between customers and our servers is fully encrypted using industry-standard SSL/TLS protocols. Data is stored across top-tier cloud environments that incorporate rigorous, multi-layered physical and logical protection to ensure constant compliance and safety.

Penetration Testing and Security Assurance

Idomoo conducts comprehensive penetration testing twice a year, performed by independent, certified security professionals. These expert testers simulate real-world attack scenarios across our platform to identify and isolate vulnerabilities before they can be exploited.

All findings are triaged, prioritized by severity and fully remediated. This biannual testing cadence ensures that Idomoo’s platform remains resilient against evolving threats.

Security FAQs

Idomoo holds a comprehensive set of internationally recognized certifications and complies with leading global privacy regulations. On the information security side, we are certified to ISO 27001, ISO 27799 and ISO 42001 and have completed an independent SOC 2 Type 2 examination. On the privacy and regulatory side, our platform is fully aligned with GDPR, HIPAA and CCPA.

Data in transit: All data transfers utilize secure protocols backed by robust authentication. Idomoo provides dedicated, secure SFTP accounts for batch data file transfers and mandates HTTPS for all API interactions. To ensure message origin and integrity, we enforce API key authentication, with the additional option to implement IP whitelisting for enhanced security.

Data at rest: Idomoo does not permanently store customer personal data. Data is fully encrypted while at rest during the video generation process and is immediately deleted upon completion. This means no backups of customer-personalized data are retained. For files uploaded via SFTP, an automated system cleanup permanently deletes any remaining files after 7 days if they have not already been removed by the client.

Idomoo conducts comprehensive penetration testing twice a year using independent, highly certified security professionals. These tests simulate advanced, real-world attack scenarios across the entire platform to identify potential vulnerabilities. All findings are rigorously triaged, prioritized by severity, and fully remediated with strict closure tracking.
Idomoo complies with GDPR, HIPAA and CCPA. We offer a Data Processing Addendum (DPA) to customers handling EU personal data and Business Associate Agreements (BAA) for healthcare customers. Your data is accessible only to you, and we are fully transparent about how it is used.

Idomoo’s infrastructure is hosted on AWS with strict regional data isolation to ensure data never leaves its assigned region at any point in the process.

 

  • U.S. and Rest of the World Customers: Primary deployment is hosted in the AWS North Virginia region with AWS Oregon serving as the secondary location.
  • EU Customers: Primary deployment is hosted in the AWS Dublin (Ireland) region, with AWS Frankfurt (Germany) serving as the secondary location.

Personalize Your Video

Enter your info to receive a Personalized Video, made just for you!

First Name * Please insert valid value
Last Name * Please insert valid value
Business Email * Please enter your business email

What do you need?

Select all that apply.

Choose an option

How can we reach you?

First Name*

Please complete this required field.

Last Name*

Please complete this required field.

Phone number*

Please complete this required field.

We'll never spam you. Our use of your personal data is subject to our privacy policy.

Please complete all required fields.

Call Requested!

Thanks for reaching out. A dedicated member of the Idomoo team will be in touch with you soon to share more information and answer any questions you may have.

Request a Demo

Leave your details below, and we’ll be in touch to show you how Lucas can scale up your video content.