Security
Security overview
At a glance
- One GPU server per customer, never shared.
- All AI models run locally on that server. No outside AI services, no telemetry.
- Outbound network access is closed once the server is installed.
- Speakers without recorded consent are never cloned.
- Your data is deleted when the contract ends, and you get a deletion record.
1. Dedicated architecture
Every customer gets a GPU server set up only for them, in their region: Türkiye for customers in Türkiye, the EU for customers elsewhere. Your studio is reached at its own address with its own sign-in. Because the server is not shared, your video, voices and transcripts are never in the same place as another customer's.
2. Your data stays on your server
- Speech separation, transcription, translation, voice cloning, lip sync and quality checks all run on local, self-hosted models.
- No audio, video or text is sent to third-party AI APIs, and product telemetry is switched off.
- After installation, outbound internet access from the server is blocked.
- We do not use your content to train models.
- Only open-source components whose licences allow commercial use are shipped; a component list is available on request.
3. Consent built into the workflow
A voice cannot be cloned unless consent for that speaker is recorded, and a project cannot be approved without it. The rules are in our Voice Consent & Acceptable Use Policy.
4. Retention and deletion
Data is kept for the period set in your contract. On request we delete specific projects, and when the contract ends all project data, voice references and profiles are deleted and you receive a record of the deletion. Where we host the server, it is wiped.
5. This website
- Served only over HTTPS, with HSTS, a strict Content Security Policy and other security headers.
- No cookies, trackers or third-party scripts; fonts and media come from our own domain.
- The quote form is rate-limited and protected against spam, and requests are deleted automatically after 24 months.
6. Planned, not yet in place
We are a new company and prefer to say so plainly. The following are on our roadmap and are not in place today:
- disk encryption and access logging for voice references on customer servers;
- an independent penetration test;
- a documented incident response procedure with defined notification times;
- certification (TPN assessment for film and broadcast customers; ISO 27001 later).
Our security questionnaire answers each of these in detail and is available to prospective customers.
Request the security questionnaire
7. Reporting a vulnerability
If you think you have found a security issue in this website or in Dublayer, please email hello@dublayer.studio with enough detail for us to reproduce it. We will acknowledge your report within 3 business days and keep you updated.
Please act in good faith: do not access or change other people's data, do not disrupt the service, do not use social engineering or physical attacks, and give us reasonable time to fix the issue before telling anyone else. We will not take legal action against research that follows these rules. Our contact details are also published at /.well-known/security.txt.