Skip to content

DOUBLE CREDITS on your first month, or your first 3 months on annual

Claim now
Kyndrify
All articlesKnowledge

AI Video Vendor Security Review: What to Ask

Review an AI video vendor with practical questions on data use, training, access, deletion, and export. Compare claims with records before a sensitive pilot.

By the Kyndrify team10 min read
Share
Ethernet cables and ports inside a server rack

You want an AI video tool that saves time. You also want one that does not leak client footage, train on private recordings without consent, or leave old files sitting on a server forever. A security review sounds heavy. It does not have to be. You need a short, repeatable method that separates a vendor's marketing words from things you can check.

This guide is general information, not legal or security advice for your specific business. The scoring numbers in the worked example are illustrative choices, not industry standards or proven cutoffs.

Start with the data flow

Before you read a vendor's security page, map what you will send. Ask one question: what enters the tool, and where does it go?

For a typical small business, the flow might look like this:

  1. You upload a raw video or record directly in the tool.
  2. The tool processes it, often in the cloud.
  3. It may create a transcript, captions, or an avatar.
  4. It stores the source file and the output.
  5. You download or share the result.

Write this flow down. Then ask the vendor to confirm each step. If they cannot explain where files are processed, that is a warning sign. You do not need a diagram from them. You need plain answers.

The NIST AI Risk Management Framework is voluntary guidance to help manage AI risks to people and organizations. It is not certification, a legal obligation, or proof a vendor is secure. You can use its "Map" idea as a mental prompt: know the context before you trust the tool.

Separate statements, commitments, and controls

Vendors use three kinds of language. Learn to tell them apart.

Statements are marketing words. "We take security seriously" is a statement. It tells you nothing checkable.

Commitments are written promises. "We will not use your footage to train models" is a commitment. It matters if it appears in the contract or a signed data processing agreement. A commitment is still not proof that the technical controls work as described; it is a starting point for verification.

Controls are things you can verify. A control might be a setting that limits who can view a workspace, or a log that shows who accessed a file. Controls are stronger than words.

Your job is to move from statements to commitments to controls. If a vendor stops at statements, treat that as a gap.

The five-question core review

Use these five questions for any AI video vendor.

1. What exactly do you train on?

Ask whether your uploaded footage, transcripts, or generated videos are used to train AI models. Ask for a yes or no. Then ask where that answer appears in writing.

If the answer is "we use anonymized data," ask what anonymized means here. A face is not anonymous just because the name is removed. A voice can still identify someone. Ask specifically how face and voice identifiers are handled: are they stored, hashed, or removed before any training or processing by upstream providers?

2. Who else touches the data?

Some vendors use other firms for hosting, transcription, or rendering. These are subprocessors. Ask for a current list. Ask whether the list changes with notice. Ask whether each subprocessor has the same data protection terms.

A vendor that cannot name its subprocessors leaves you unable to assess where client data actually goes. Treat that as a significant gap.

3. How long are files kept?

The UK ICO storage limitation guidance says personal data should not be held longer than needed for the purpose. Retention must be justified and reviewed. Legal duties can justify keeping some records. UK-specific guidance is under review.

Ask the vendor for a retention schedule. "We keep files for 30 days after you delete them" is a clear answer. "We keep files as long as needed" is not.

4. How does deletion actually work?

Deletion is not one button. Ask what happens when you delete a project. Does the source file go? The transcript? The generated video? Backups?

A good answer names each type of data and gives a time window. A weak answer says "deleted immediately" with no detail. Backups may have a distinct retention schedule from active storage; the vendor should state it clearly rather than implying everything disappears at once.

5. How will you tell me about a breach?

Ask for the incident notification window. Some contracts say "without undue delay" or a set number of hours. Ask what the notice includes. Ask who receives it.

If the vendor has no incident process, that is a serious gap for most businesses handling client data.

Evidence-request table

Use this table when you talk to a vendor. Ask for each item in writing. Mark what you receive.

Area What to ask for What good looks like What weak looks like
Data flow Written description of processing locations Named regions or providers "Secure cloud" with no detail
Model training Contract clause on training use Clear opt-out or prohibition Marketing statement only
Subprocessors Current list and change process Named firms, notice period "Trusted partners"
Retention Schedule by data type Days or months per type "As long as needed"
Deletion Process for source, output, backups Named steps and time windows "Instant delete" with no backup detail
Access controls Who can view a workspace or file Role-based settings, MFA option "Only authorized staff"
Incident notice Contractual time window Hours or defined "undue delay" No process described
Export Format and method for getting data out Standard format, self-serve Manual request only

This table is an editorial tool, not an official NIST test. It helps you compare vendors on the same points.

Disqualifiers

Some answers should end the conversation. Treat these as hard stops for most small businesses:

  • The vendor will not say whether your footage trains models.
  • The vendor cannot name its subprocessors.
  • The vendor has no deletion process for backups.
  • The vendor has no incident notification commitment.
  • The vendor refuses to put security answers in the contract.

One missing item may be fixable. Three missing items are a pattern.

Fictional worked example

Let's walk through a review. This example is invented. It does not describe a real vendor.

The business: A small marketing agency, Team A, wants to create client testimonial videos with an AI avatar tool. They handle client names, faces, and voice recordings.

The vendor: Vendor A offers AI video generation. Their website says "enterprise-grade security."

Step 1: Data flow. Team A asks where files are processed. Vendor A says processing happens in the EU and the US. They name their cloud provider. Good.

Step 2: Training. Team A asks if client footage trains models. Vendor A says no. Team A asks for that in the contract. Vendor A agrees to add a clause. Good.

Step 3: Subprocessors. Vendor A sends a list of three firms: one for hosting, one for transcription, one for rendering. The list includes locations. Good.

Step 4: Retention. Vendor A says source files are kept for 90 days after project deletion. Transcripts are kept for 30 days. Backups are kept for up to 180 days. Team A accepts this because it is specific.

Step 5: Deletion. Vendor A explains that deleting a project removes the source and output from active storage within 24 hours. Backups expire on the retention schedule. Team A notes this in their records.

Step 6: Access controls. Vendor A shows that workspace owners can invite members with viewer or editor roles. MFA is available. Team A turns it on for all staff.

Step 7: Incident notice. Vendor A's contract says they will notify customers within 72 hours of confirming a breach. Team A accepts this.

Step 8: Export. Vendor A lets Team A download videos in MP4 and transcripts in plain text. Good.

Scoring. Team A uses a simple 1–5 scale for each area. This is their own illustrative choice, not a proven cutoff.

Area Score (1–5) Note
Data flow 4 Clear locations, no diagram
Training 5 Contract clause added
Subprocessors 4 List provided, change notice vague
Retention 4 Specific, backups lag
Deletion 4 Clear process, backup delay stated
Access controls 5 Roles and MFA
Incident notice 4 72-hour window
Export 5 Self-serve, standard formats

Total: 35 out of 40. Team A sets a threshold of 30 to proceed. Vendor A passes. Team A documents the answers and reviews them yearly.

This scoring is hypothetical and unvalidated. A high total does not mean every risk is covered; a critical gap in one area cannot be averaged away by strong scores elsewhere.

Edge cases

You record client interviews on your own device. The AI tool only receives the file you upload. Your device security is still your job. Encrypt the device. Limit who can access it.

You use a free tier for a test. Free tiers often have weaker terms. Do not test with real client footage. Use a sample recording with no personal data.

A client asks you to delete everything. You can delete from the AI tool. You may still have local copies. Tell the client what you can and cannot remove. Do not promise deletion of backups you do not control.

You work with a subcontractor. Your subcontractor may upload footage to their own AI tool. Your vendor review does not cover that. Add a clause in your subcontractor agreement about AI tools.

The vendor changes their terms. A vendor can update their privacy policy. Ask for notice of material changes. Re-run the review if training or subprocessor terms change.

Three short FAQs

Q: Is a security certification enough? A: No. Certifications can help, but they are not proof a vendor handles your specific data well. Ask the five core questions anyway. A certificate is a starting point, not a finish line.

Q: What if the vendor will not answer in writing? A: Treat verbal answers as unverified. If a vendor will not put a training or deletion answer in the contract, assume the weaker position. Walk away if the data is sensitive.

Q: How often should I re-review a vendor? A: At least once a year, or when the vendor changes terms, adds subprocessors, or launches new features. A short annual check takes less than an hour.

Useful context

If you are still choosing a tool, read Is AI video privacy friendly? for a plain-language look at the tradeoffs. If you are comparing avatar tools, What to look for in an AI avatar tool covers feature and workflow questions. If you run an agency, AI video for agencies discusses client-facing decisions.

For current details on one platform's published security practices, see the Kyndrify security page. That page says private media access is scoped to workspaces, MFA is available, and Kyndrify is not HIPAA-eligible. Do not turn published statements into independently audited guarantees. Check the page directly for current details.

Your next action

Pick one vendor you already use or are considering. Send them the five core questions today. Ask for answers in writing. Put the responses in the evidence table. If any answer is missing or vague, ask again. One hour now can prevent a client data problem later.

ai video vendor security review

Make your first video without filming.

Say what you need and the studio makes it: video, images, voices. Start free, no credit card.