Trust

Compliance Center

Framework readiness for RTAS Studio AI — what ships today versus what remains on the roadmap. We align practices with GDPR/CCPA expectations where applicable; we do not claim to be “GDPR certified,” SOC 2 certified, or ISO certified.

Compliance matrix

Legal policy suite

Implemented

Terms, Privacy, Cookies, Refund, AI Usage, Trust & Safety, Community Guidelines, Copyright & DMCA.

Cookie consent (Necessary / Analytics / Marketing)

Implemented

Banner + preference center; optional trackers gated before load.

Self-serve data export & deletion request

Implemented

Signed-in Privacy settings: JSON export and deletion ticket workflow.

GDPR / CCPA readiness

Partial

Policy disclosures, rights language, and operational workflows. Not a formal certification or supervisory approval.

Encryption in transit (TLS)

Implemented

Web and API traffic over TLS; secrets remain server-side.

Data storage & subprocessors

Implemented

Account and studio data in configured cloud database/storage; payments via Paddle MoR; AI inference via configured providers.

Privacy controls (email + cookies)

Implemented

Notification preferences and cookie category controls in-product.

Customer DPA template

Roadmap

Enterprise DPA pack for countersignature — not published as self-serve.

SOC 2 Type I/II

Roadmap

Attestation not obtained. Do not display SOC badges.

ISO 27001

Roadmap

ISMS certification not obtained.

Privacy: privacy@rtasstudio.com · Legal: legal@rtasstudio.com