Eddie AI has completed a SOC 2 Type II audit, on top of the SOC 2 Type I we finished earlier, and we are now GDPR certified.
The badge on our site has moved from Type I to Type II. That is a one-word change and it represents about as much work as anything else we have done this year, so it is worth explaining what actually changed rather than just swapping the logo and moving on.
What SOC 2 Type I was
A SOC 2 Type I report is an independent auditor looking at your security controls on a particular day and saying: yes, these are designed properly, and yes, they were in place when I looked.
That is a real thing. It is not nothing. Someone outside the company reads how you handle access to production, how you encrypt data, how you onboard and — more importantly — offboard people, how you decide which vendors get to touch customer data, and confirms the controls are sensibly designed and genuinely exist.
But it is a photograph. It says the room was tidy on the day the inspector came.
What Type II adds
A SOC 2 Type II report is the same auditor watching those controls over a period of months and testing whether they actually operated the whole time.
That is the harder test, and it is the one that matters, because the failure mode of security is almost never "we never had a policy." It is "we had a policy and then it was a busy quarter." Type II is designed to catch exactly that. The auditor pulls samples across the window: every person who joined and left, every change that shipped to production, every access review that was supposed to happen, every alert that fired. If access reviews were meant to run quarterly and one got skipped in month four, that shows up. There is no version of the report where you tidy the room the night before.
So the honest summary of the difference: Type I says our controls are well designed. Type II says we actually ran them, continuously, and someone independent checked the evidence rather than taking our word for it.
Both reports are available under NDA. Our Trust Center has the current documentation, the scope, and the request process, and the AICPA mark on our site links to aicpa.org/soc4so if you want to read what SOC for Service Organizations covers in general.
And GDPR
Separately, we are now GDPR certified.
SOC 2 is about whether you protect data properly. GDPR is about whether you have the right to be holding it at all, and what the person it belongs to can ask you to do about it. Different question, different work.
In practice that meant getting concrete about things that are easy to leave vague: what personal data we collect and why, the legal basis for each of those purposes, how long we keep it, which sub-processors we use and what they are allowed to do, how data moves between regions and under which transfer mechanism, and how someone exercises their rights — access, correction, deletion, portability, objection — and how quickly we have to answer.
If you are in the EU or the UK, the practical points: we have appointed a Data Protection Officer, and EU and UK Article 27 representatives, both named in our Privacy Policy. We have a DPA you can execute. Requests go to privacy@heyeddie.ai and we answer within the statutory timeframe.
What this does and does not mean for your footage
Worth being precise here, because compliance language invites overclaiming and this is an area where overclaiming is genuinely harmful.
What these audits cover. That we have designed and continuously operated controls around the systems that hold your media and your account data, and that an independent third party tested the evidence rather than reading our marketing.
What has not changed, because it was already true. Your footage is yours. We do not train models on your media. We do not watch your rushes. Nothing gets licensed back to us. Those were our commitments before any auditor showed up and they are the same commitments now — the audits are simply why you no longer have to take them on faith.
What no audit means. SOC 2 Type II is not a guarantee that nothing will ever go wrong, and any vendor who implies otherwise is selling you something. It is evidence of a system: controls that are designed, operated, monitored, and checked by someone with no stake in the answer. That is a considerably better basis for trusting a vendor than a page of adjectives, and it is still not a promise about the future.
Why we did it
Mostly because of who Eddie is for.
Editors do not own the footage they cut. It belongs to a broadcaster, an agency, a brand, a client under embargo, a documentary subject who agreed to be filmed on specific terms. When one of those editors wants to bring a new tool into their post workflow, they often cannot just try it — someone in legal or IT has to sign off first, and that person's job is to ask for the report, not the demo.
For a long time the honest answer to "can I put my client's unreleased footage through this?" was our word. Now it is a document, and a second document covering the period since the first one, and a third for anyone whose data protection questions come with a legal basis attached.
Same answer as before. Better evidence.
If you need the reports, the scope, or a DPA, everything starts at trust.heyeddie.ai, or email us at hey@heyeddie.ai.