Data and media
AES-128/256 encryption and DRM for video, encrypted databases, disks, files, and communication channels.
The controls that protect an adult platform's media, APIs, accounts, and data, and the certifications and agreements enterprise buyers ask for.
UPDATED
The underlying platform is independently audited and operates under a published set of legal agreements.
SOC 2 and ISO 27017/27018 are not currently listed. Current certificates, audit scope, and reports are available on request under NDA.
AES-128/256 encryption and DRM for video, encrypted databases, disks, files, and communication channels.
Two-factor authentication, token-based API access, and scoped credentials for infrastructure management.
Tokenised and signed URLs, forced HTTPS, CORS control, and private origins behind signed delivery.
Intrusion detection, firewalling, vulnerability scanning, hardened virtualisation, and trusted computing.
Network and application attacks are absorbed across a global edge with 200+ Tbps of filtering capacity, mitigating volumetric attacks above 1 Tbps. Protection spans layers 3, 4, and 7, with always-on mitigation for advanced plans, BGP and GRE traffic redirection, and anycast routing.
Cache-busting attacks, which force origin fetches by making every request unique, are the highest-impact application-layer threat to a video platform. Mitigation is inline and automatic rather than a manually triggered mode, and event logs are retained for review.
A web application and API protection layer covers the login, search, media, creator, messaging, and payment surfaces.
A data processing agreement forms part of the master services agreement and defines processor and controller roles, sub-processing, and cross-border transfer terms. Personal data is retained for the term of the agreement plus ten years where required by data protection law.
Workloads run across regions in the Americas, EMEA, and APAC, with regional placement available for data-residency requirements. Customer accounts are subject to KYC verification, and access to account details is restricted internally.
Abuse is handled under a published service abuse policy and copyright policy, with a dedicated abuse reporting channel and transparency reporting aligned to the EU Digital Services Act. The platform operates as an intermediary and acts expeditiously on valid reports.
Incident response, logging, and escalation are defined in the service specifications. Security reports, monitoring details, and documentation are available through the trust center on request.
Request the current certificates, audit scope, data processing agreement, and security reports under NDA.
The underlying platform holds ISO 27001 and PCI DSS (annual QSA audit for cloud) and operates in compliance with GDPR. SOC 2 and ISO 27017/27018 are not currently listed. Certification scope and current reports are available on request.
Yes. A data processing agreement is part of the master services agreement and covers processor and controller roles and cross-border transfer terms.
Media is protected with tokenised and signed URLs, forced HTTPS, CORS control, and AES-128/256 encryption with DRM for video. Originals stay private behind signed delivery.
Abuse is handled under a published service abuse policy and copyright policy, with a dedicated abuse reporting channel and transparency reporting. The platform operates as an intermediary and acts on valid reports.
Workloads run across regions in the Americas, EMEA, and APAC, with regional placement available for data-residency requirements.