// security & trust

Last reviewed: August 17, 2026

TRUST AS A CONSTRAINT.

Most platforms treat rights, consistency, and compliance as documents. We treat them as programmable constraints: enforced in code and database checks, tested against production. Everything on this page is live behavior, not intention.

Consent is a gate, not a checkbox

Every generation route resolves the licence before the model is called. For a model enrolled in the rights programme the check is strict — ownership, status, expiry, usage cap, territory, revocation and licence class — and an unlicensed request is refused with a 402 before any engine runs. Said plainly, because the code says it too: the gate fails OPEN for a model outside the programme, so that legacy work is not stopped, and a failure of the lookup itself also passes through rather than blocking. Enrolment is what the guarantee attaches to.

Every use writes an immutable receipt

Each generation with a licensed identity produces a receipt on an append-only ledger and records the talent's royalty automatically. Usage is auditable per render: for brands, talent, and partner platforms alike.

Tenant isolation, tested continuously

Every studio's jobs, assets, folders, galleries, and scores are isolated by row-level security and explicit ownership checks. A 50-test authorization suite exercises these boundaries against the live database: cross-tenant reads are structurally denied.

You own every output

Assets generated in your workspace are yours: full commercial ownership, with provenance metadata embedded on delivery. We never use your data to train shared or third-party models; custom models trained on your assets belong to your workspace alone.

Brand consistency you can inspect

Generations against a locked brand DNA are scored across seven visual dimensions and recorded in an audit table your team can read. On-brand is a measured property, not a promise.

Sustainability, signed

Each delivery can carry a hash-verified CO₂e certificate quantifying emissions avoided versus a physical shoot: a verifiable artifact, not a marketing estimate.

The three commitments

  • You retain full ownership of every generated asset.
  • We do not use your data to train shared models.
  • An enrolled identity is checked against an active licence before generation — and where that check fails open, our auditor brief says so rather than this page claiming it never does.

Questions, answered.

Who owns the images and films Studio Munich generates for us?

You do. Every asset generated in your workspace is yours to use commercially, with provenance metadata embedded on delivery.

Is our data used to train AI models?

No. We never use client data to train shared or third-party models. Where you commission a custom model on your own assets, that model is scoped to your workspace alone.

How is talent likeness protected?

Real faces and voices are licensed through consent-backed identity tokens, and the database refuses a model seat that names a typed name rather than a talent record. Two limits we would rather state than have found: a model outside the rights programme passes through, and if the licence lookup itself errors the request is allowed rather than refused — which matters under load, because load is when lookups fail. Licensed use is built to write a receipt and record a royalty; that ledger has not yet accrued one.

How is our data separated from other customers?

Row-level security plus explicit studio-ownership checks on every surface: productions, assets, folders, client galleries, and audit scores. A continuously-run authorization test suite verifies these boundaries against the production database.

Where is data stored and how is it encrypted?

Data is stored with our cloud providers encrypted at rest and in transit (TLS). Contact us for data-processing details for your compliance review: we support GDPR-aligned agreements.

Need documentation for a compliance review, or want the enforcement walked through live?

Talk to engineering