skeet
Pricing
Log in
skeet

A video editor that has already watched your footage. In the browser, where everyone is.

Product

  • Studio
  • Clive
  • Skeet on the desktop
  • Skeet on a phone
  • Publishing
  • Color
  • Monitoring
  • Audio
  • The schedule
  • Versions and history
  • Keeping a look consistent

Solutions

  • Independent Creators
  • Conversational Media
  • Social Media Pros
  • Streamers
  • Production Studios
  • Founder-Led Content
  • Live Commerce
  • Narrative Film
  • Product & Tech Teams
  • Education & EdTech

Resources

  • Docs
  • Changelog
  • System requirements
  • Learn
  • Community
  • Security
  • Pricing

Company

  • About
  • Contact
  • Careers
  • Brand
Start editing
© 2026 Skeet, Inc.
  • Privacy
  • Terms
  • Cookies
  • Acceptable use
  • Subprocessors

Last updated July 29, 2026

Security

How we protect your media and account data, and an honest account of what we have not built yet.

Contents

  1. Our approach
  2. Encryption
  3. Access control
  4. Infrastructure
  5. Telemetry and logging
  6. What you control
  7. Where we are not yet
  8. Reporting a vulnerability

01.Our approach

You hand us raw footage, which is often unreleased, sometimes commercially sensitive, and occasionally the only copy. We treat it that way. This page describes the controls we actually run today, and it is deliberately specific about what we have not built yet.

02.Encryption

  • In transit. All traffic between your browser, our API, and our storage runs over TLS.
  • At rest. Uploaded media, rendered output, and database content are encrypted at rest.
  • Payment data. Full card numbers never reach our systems. They go directly to our payment processor and we hold only a tokenised reference.

03.Access control

  • Multi-factor authentication is mandatory for every engineer with production access.
  • Every sub-processor is issued scoped credentials limited to the function it performs. No provider holds a general-purpose key.
  • Access logs are reviewed as a matter of routine rather than only after an incident.
  • Media objects are stored in private buckets and served through a restricted-origin CDN distribution rather than public URLs.

04.Infrastructure

Skeet runs on Amazon Web Services in the United States (US-East). Compute runs on ECS, object storage on S3, and delivery through CloudFront. The full list of providers that touch your data is on our sub-processors page.

05.Telemetry and logging

Error and performance telemetry is scrubbed and aggregated before it leaves our systems, so crash reports do not carry your media or message contents. We collect what we need to keep renders working, not a behavioral profile.

06.What you control

  • You can delete projects and assets from your account, and deletion propagates to our object storage.
  • You can export your work rather than being locked to our platform.
  • You can request a copy of your personal data, or its deletion, by writing to us. See the Privacy Policy for the process and our response times.

07.Where we are not yet

Security pages tend to imply more than is true. Ours should not, so here is the current state plainly:

  • We do not hold SOC 2, ISO 27001, or any equivalent third-party certification.
  • We have not completed an independent penetration test.
  • We do not operate a paid bug bounty programme, though we do respond to reports.

We are a small team and we would rather tell you this than let a badge imply otherwise. If your organization requires any of the above before adopting a tool, talk to us about timelines instead of assuming.

08.Reporting a vulnerability

If you believe you have found a security issue, email security@skeet.now. Include enough detail to reproduce the issue, and give us a reasonable window to respond before disclosing publicly.

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and do not access or modify data belonging to other users.