Skip to content
AIHeadshotInstant logoAIHeadshotInstant
SECURITY

Security Policy

How we protect your photos, accounts, and payment data — and how to report a vulnerability.

Encryption

All photo uploads, model weights, and generated headshots are encrypted in transit (TLS 1.3) and at rest (AES-256). Authentication tokens never leave secure HTTP-only cookies.

Infrastructure

We run on Cloudflare Workers and Cloudflare R2 with strict-origin egress. Payment processing is handled by Stripe — we never see or store full card numbers.

Compliance

We operate under EU GDPR and California CCPA. A Data Processing Agreement (DPA) is available on request — email legal@aiheadshotinstant.com.

Data deletion

Selfies auto-delete within 24 hours. Generated headshots auto-delete within 30 days. Account deletion (with all associated data) is one click in the dashboard, and irrevocable within 24 hours.

Reporting a vulnerability

If you've found a security issue, please email security@aiheadshotinstant.com with a description, reproduction steps, and any relevant screenshots. We aim to acknowledge within 24 hours and patch critical issues within 72 hours.

Security Policy | AIHeadshotInstant