Last updated 27 August 2026
Security
Belgrave is used on picture that is not public yet. This page is how we treat that, in the app and on the wire.
On the machine
Local projects stay on disks you control. The Windows app does not upload media unless you create a share or a vault item. Licence checks send a device id and the seat, not the timeline.
Shares
A share is a link with optional passcode, expiry, watermark and download off. Recipients install Belgrave on Windows to open it. We log opens so you can see if a room was forwarded. Forensic watermarks on Studio encodes the seat that issued the share.
Transport and storage
TLS for the site, the licence service and share playback. Vault objects are encrypted at rest in a European region. We do not put production media in a US-only bucket as a default.
Access inside Belgrave
Named seats. Studio can require SSO. We do not use shared “edit” passwords. Staff access to customer vaults is ticketed, logged, and off unless you ask for support on a specific project.
Report a problem
If you find a vulnerability, email security@belgravearchive.com. Please give us a chance to fix it before you post it. We will acknowledge within two business days. This is not a bounty programme with a price list; we will still take it seriously.