INVITE-ONLY BETA Request beta access
SECURITY & PRIVACY

Your footage stays yours.

Editing is local-first: your projects and media live on your device and never leave it unless you choose to. Here's exactly how sign-in, the cloud, and provenance work — described plainly, with nothing overclaimed.

ON YOUR DEVICE

Local by default. Cloud only when you say.

Projects and media live on your machine. Clips decode and play back locally — nothing is uploaded to edit.
Horoptic doesn't train on your media. Your footage is never used to train a Horoptic model, and we never sell or hand it over as training data.
Generation requests stay minimal. When you approve a generation, only that request goes to the model provider — never your library, and never more than the job needs. We keep a provenance record of what was made, not a dataset of your media. The provider then handles that request under its own terms, which is why we list who they are rather than make promises on their behalf.
WHERE YOUR PROJECT LIVES
Sync, the Director, generation and server-rendered masters need the cloud. Everything else stays on your device — no account, no upload.
PROVENANCE

Every export accounts for what went into it.

Every master records a C2PA manifest by default: one composite AI declaration covering the file, and every source clip fingerprinted with SHA-256 alongside a hash of the delivered file. It is recorded with your master rather than embedded in it today — embedding and public verification ship with our signing certificate.

HOW IT'S BUILT

A small, boring, careful backend.

The parts that touch the cloud are split so the sensitive bits stay server-side. Plainly:

CLIENT
Your device
The editor, your media and the op-log. Talks to the cloud only when you promote a project.
CONTROL PLANE
Cloudflare
Auth, sync and orchestration. Coordinates work; holds the keys the client never sees.
HEAVY LIFTING
Render worker
A separate worker for server-side masters and generation jobs — isolated from the control plane.
EXTERNAL
Model providers
Called server-side to do generation. We send only what the job needs — your library is never handed over wholesale — and we keep no copy of it beyond the provenance record. What a provider does with a request is governed by its own terms.
Provider API keys live server-side. They're never shipped to your machine, and they're never exposed to the browser.
What we're not claiming, yet.

This is an invite-only beta. We're describing our posture and practices — not advertising formal certifications. We don't claim SOC 2 or ISO reports, "compliant" badges, or enterprise guarantees we haven't earned. When there's something certified to show, we'll show it here — and not before.

CLOSED BETA · INVITE-ONLY

Keep your footage. Get the app.

The local editor is free, offline and account-less — a native desktop app for macOS and Windows. Request an invite to the closed beta.

A native app for macOS & Windows — no browser editor Have an invite code?