Skip to content
Notifications
Clear all

Reaction to their latest security whitepaper - any red flags for enterprise?

1 Posts
1 Users
0 Reactions
3 Views
(@averyd)
Estimable Member
Joined: 1 week ago
Posts: 120
Topic starter   [#10769]

Having spent the morning analyzing HeyGen's newly published security whitepaper, I'm left with a mixed impression. While they've made a commendable effort in transparency—covering data encryption (at-rest/in-transit), SOC 2 compliance, and a general shared responsibility model—the document feels more like a marketing prerequisite than a deep technical dive. For a product handling such sensitive biometric data (voice and likeness), the devil is truly in the details, many of which seem absent.

A few points stood out to me, or rather, didn't:

* **Data Residency & Sovereignty:** The whitepaper is conspicuously silent on specific data center regions or commitments to keep data within certain geopolitical boundaries (e.g., EU, US-only). For any enterprise subject to GDPR, CCPA, or other regional regulations, this is a critical gap. Can we define where our training data and generated assets are stored?
* **Vendor Sub-processor Disclosure:** There's no listed annex of sub-processors (AWS, Azure, etc.). Enterprises need to map their data flows and understand the entire chain of custody. This lack of detail complicates security questionnaires and third-party risk assessments.
* **Incident Response & Retention Policies:** While they mention security monitoring, the specifics of breach notification timelines, forensic capabilities, and—crucially—their data retention and deletion protocols for uploaded source materials are vague. How long is my CEO's video training data kept after model creation? Can I enforce a custom retention schedule?

From a FinOps perspective, this also ties into risk costing. A vague security posture can lead to protracted legal/compliance reviews, which delays deployment and creates hidden project costs. It can also affect insurance.

My question to the community: has anyone engaged with their enterprise sales or security team directly on these points? I'm particularly interested in any concrete SLAs or contractual terms you've been able to negotiate regarding data locality and deletion. The whitepaper, as it stands, feels like a foundation, but not yet a complete blueprint for enterprise trust.

—A


Every dollar counts.


   
Quote