Security and Compliance
We support our customers’ compliance with privacy laws, including GDPR, CCPA and HIPAA, and offer a Data Processing Addendum and Business Associate Agreement. Idomoo’s platform has been evaluated by an independent third-party auditor to confirm that our controls align with industry standards for security and confidentiality.Our Accreditations

ISO 27001
Information Security Management Systems

ISO 27799
Health Informatics – Information Security Management in Health

ISO 42001
Artificial Intelligence Management System

SOC 2 Type 2
System and Organization Controls 2 Type 2 compliance

GDPR
EU General Data Protection Regulation

HIPAA
Health Insurance Portability and Accountability Act

CCPA
California Consumer Privacy Act

Cyber Essentials
U.K. government-backed security credential
Need More?
Our Security Practices
ISO 27001 – Certified Information Security Management Systems
Idomoo is certified to ISO 27001, the international standard for information security management. This certification is awarded by an accredited third-party body and confirms that we operate a structured, risk-based approach to protecting information assets. Our certification covers policies, technical and organizational controls and full documentation of security procedures.
Audits are conducted periodically to verify continuous compliance with the standard’s requirements. ISO 27001 certification means our customers can trust that Idomoo operates a secure, reliable, and consistent security environment.
Maximum Data Protection
Data security begins at the encryption layer and continues through every stage of its lifecycle, from active transmission to storage within our secure cloud infrastructure.
All communication between customers and our servers is fully encrypted using industry-standard SSL/TLS protocols. Data is stored across top-tier cloud environments that incorporate rigorous, multi-layered physical and logical protection to ensure constant compliance and safety.
Penetration Testing and Security Assurance
Idomoo conducts comprehensive penetration testing twice a year, performed by independent, certified security professionals. These expert testers simulate real-world attack scenarios across our platform to identify and isolate vulnerabilities before they can be exploited.
All findings are triaged, prioritized by severity and fully remediated. This biannual testing cadence ensures that Idomoo’s platform remains resilient against evolving threats.
Security FAQs
What international security standards does Idomoo comply with?
How is my data protected from leakage or exposure?
Data in transit: All data transfers utilize secure protocols backed by robust authentication. Idomoo provides dedicated, secure SFTP accounts for batch data file transfers and mandates HTTPS for all API interactions. To ensure message origin and integrity, we enforce API key authentication, with the additional option to implement IP whitelisting for enhanced security.
Data at rest: Idomoo does not permanently store customer personal data. Data is fully encrypted while at rest during the video generation process and is immediately deleted upon completion. This means no backups of customer-personalized data are retained. For files uploaded via SFTP, an automated system cleanup permanently deletes any remaining files after 7 days if they have not already been removed by the client.
How do you ensure your platform is protected against breaches?
How do you protect my privacy and meet legal requirements?
What is the location of your data?
Idomoo’s infrastructure is hosted on AWS with strict regional data isolation to ensure data never leaves its assigned region at any point in the process.
- U.S. and Rest of the World Customers: Primary deployment is hosted in the AWS North Virginia region with AWS Oregon serving as the secondary location.
- EU Customers: Primary deployment is hosted in the AWS Dublin (Ireland) region, with AWS Frankfurt (Germany) serving as the secondary location.