Security & Trust
Built for
brand-safe scale.
Generate thousands of on-model images with the controls a brand needs — clear data handling, honest compliance, responsible AI, and rights you actually own.
Trust, at a glance
- GDPR-aligned — Available
- DPA available — Available
- EU / US hosting — Available
- Encryption in transit & at rest — Available
- No training on your private uploads — Available
- SOC 2 Type II — in progress — In progress
How we operate
Security by default.
The practices behind every image you generate.
- Data handling & retention
- Your uploads and generated images are yours — stored only to run the service.
- Delete assets anytime; deleted files are purged from primary storage promptly and from backups within 30 days.
- We never sell your data, and we don't use your private uploads to train models shared with other customers.
- Hosting & subprocessors
- Hosted on leading enterprise cloud infrastructure, with EU and US regions.
- Encrypted in transit (TLS) and at rest.
- A short, vetted list of subprocessors — hosting, email, analytics, payments — documented in our DPA and kept current.
- Access & accounts
- Least-privilege internal access, scoped to what each role needs.
- SSO / SAML available on Enterprise, with role-based team seats.
- Sensitive actions are logged for audit.
Responsible AI
Synthetic models. No deepfakes.
On-model imagery should be brand-safe by construction — not a liability waiting to surface.

- Our models are synthetic and AI-generated — not real identities scraped from the web.
- We don't build deepfakes, and we won't replicate a specific real person's likeness without documented consent and rights.
- Safety guardrails filter unsafe or infringing generations before they reach you.
- We honor takedown and appeal requests, and keep a human path open for edge cases.
Ownership
You own every image.
Full commercial usage rights on everything you generate — no model releases, no licensing, no royalties. Put it on your PDP, your ads and your lookbook, for as long as you like.
- No model releases
- No licensing
- No royalties
- Yours forever
Compliance
Where we are — honestly.
We'd rather tell you what's true today than claim a badge we haven't earned.
- Data Processing Agreement (DPA)
- Available now — Available
- GDPR & CCPA alignment
- In place — Available
- Encryption in transit & at rest
- Standard — Available
- Data residency (EU / US)
- Available — Available
- SOC 2 Type II
- On our roadmap — On the roadmap
- Independent penetration testing
- Planned — On the roadmap
SOC 2 Type II and third-party penetration testing are on our roadmap — not yet certified. Ask sales for our current security packet and subprocessor list.
Documents
Read the fine print.
The agreements and live status behind the product.
- Data Processing Agreement
- How we process personal data on your behalf, with our subprocessor list.Read the DPA
- Privacy Policy
- What we collect, why, and the choices you have.Read privacy
- Terms of Service
- The terms that govern your use of NoShot.Read terms
- System status
- Live uptime and incident history for the platform.View status
Talk to our team
about security.
Enterprise reviews, DPAs, SSO and data-residency questions — we'll walk you through it.