Security at Hinto AI
Last Updated: September 7, 2026
1. Overview
Hinto AI turns screen recordings into documentation. Your recordings, the documents generated from them, and your account data are the assets we protect. Hinto AI is a trading name of Vertex Tree LTD (England and Wales, company number 15229327).
2. Reporting a vulnerability
If you believe you have found a security issue in Hinto AI, email security@hintoai.com. A machine-readable version of this policy is published at /.well-known/security.txt.
- Include the affected URL or API endpoint, steps to reproduce, and the impact you observed. Proof-of-concept requests are welcome. Please do not include other people's data.
- We acknowledge reports within two business days and give a first assessment within seven days.
- Remediation targets once confirmed are 7 days for critical, 30 days for high, and 90 days for medium severity.
- We will not pursue legal action against researchers who act in good faith, stay within the scope below, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before publishing.
- In scope are hintoai.com, app.hintoai.com, published documentation sites on *.hintoai.com and customer domains, and the public API. Out of scope are denial of service, social engineering, physical attacks, and findings on third-party services we do not operate.
- We do not run a paid bug bounty. We credit researchers who ask to be credited.
3. Where your data lives
- Your database records and uploaded files are stored with a managed provider in the European Union, encrypted at rest and in transit.
- The application and video processing run on servers in the European Union behind a firewall that exposes HTTPS only.
- The database is backed up daily. Deleting your content is a hard delete of the record and its files.
- The providers we use, with their locations, are listed on the sub-processors page.
4. Account security
- Sign in with email and password or with Google. Two-factor authentication with any authenticator app is available to every account, and workspace owners can require it for all members.
- You can sign out of every other device from your account security page.
- Workspace owners and members, and project owners, editors and viewers, have separate permissions. Every request is authorised against your membership before any data is read.
5. Audit log
Sign-ins, two-factor events, membership and role changes, sharing, API keys, webhooks, publishing, deletions, exports and billing events are recorded in an append-only log kept for 400 days. Workspace owners can filter it and download it as CSV from workspace settings.
6. API and integrations
- API keys belong to one project, carry the scopes you choose, are shown once and can be revoked at any time.
- Webhooks are signed with a per-project secret so your endpoint can verify every delivery. See the API documentation.
7. Contact and related pages
Security reports go to security@hintoai.com. Everything else goes to contact@hintoai.com. See also the Privacy Policy, the Data Processing Agreement, the sub-processors list and the changelog, which carries a security line on every release.