Trust
Security Center
How RTAS Studio AI protects accounts and what you can do today. Status labels are honest: Implemented, Partial, or Roadmap — never fabricated audit certifications.
Account security
Password & sign-in
ImplementedEmail/password accounts can reset credentials via Forgot password. Google OAuth accounts authenticate with Google — we never store Google passwords.
Email verification
ImplementedSensitive API routes require a verified email when verification is enabled for the account.
Active sessions
PartialAuth uses JWT sessions (up to 30 days). Privacy settings show the current browser session. Multi-device session list and remote revoke are Roadmap.
Two-factor authentication (2FA)
RoadmapTOTP / passkey 2FA is not shipped. Marked Roadmap — do not claim MFA is available today.
Security tips
- Use a unique password and enable a password manager.
- Never share Credits, API keys, or admin secrets in chat or screenshots.
- Only upload likenesses you are authorized to use (Identity Preservation).
- Sign out on shared devices after Studio sessions.
- Treat unexpected “verify your account” emails carefully — check the From domain.
Platform practices
Encryption in transit
ImplementedTLS for web and API traffic. Secrets stay server-side.
Payment webhook integrity
ImplementedMerchant-of-Record webhooks fail closed on invalid signatures.
Rate limiting
ImplementedSensitive forms and APIs apply rate limits to reduce abuse.
SOC 2 / ISO 27001 certification
RoadmapNot obtained. We maintain a compliance-ready posture and documentation — not a certification badge.
Suspicious activity
If you see unrecognized logins, unexpected Credit usage, or phishing that impersonates RTAS Studio AI, sign out, reset your password if you use credentials, and email support@rtasstudio.com with the account email, approximate time, and any job IDs. Copyright issues: legal@rtasstudio.com. General: contact@rtasstudio.com.