Trust

Security Center

How RTAS Studio AI protects accounts and what you can do today. Status labels are honest: Implemented, Partial, or Roadmap — never fabricated audit certifications.

Account security

Password & sign-in

Implemented

Email/password accounts can reset credentials via Forgot password. Google OAuth accounts authenticate with Google — we never store Google passwords.

Email verification

Implemented

Sensitive API routes require a verified email when verification is enabled for the account.

Active sessions

Partial

Auth uses JWT sessions (up to 30 days). Privacy settings show the current browser session. Multi-device session list and remote revoke are Roadmap.

Two-factor authentication (2FA)

Roadmap

TOTP / passkey 2FA is not shipped. Marked Roadmap — do not claim MFA is available today.

Security tips

  • Use a unique password and enable a password manager.
  • Never share Credits, API keys, or admin secrets in chat or screenshots.
  • Only upload likenesses you are authorized to use (Identity Preservation).
  • Sign out on shared devices after Studio sessions.
  • Treat unexpected “verify your account” emails carefully — check the From domain.

Platform practices

Encryption in transit

Implemented

TLS for web and API traffic. Secrets stay server-side.

Payment webhook integrity

Implemented

Merchant-of-Record webhooks fail closed on invalid signatures.

Rate limiting

Implemented

Sensitive forms and APIs apply rate limits to reduce abuse.

SOC 2 / ISO 27001 certification

Roadmap

Not obtained. We maintain a compliance-ready posture and documentation — not a certification badge.

Suspicious activity

If you see unrecognized logins, unexpected Credit usage, or phishing that impersonates RTAS Studio AI, sign out, reset your password if you use credentials, and email support@rtasstudio.com with the account email, approximate time, and any job IDs. Copyright issues: legal@rtasstudio.com. General: contact@rtasstudio.com.