Dream Engine Logo

Dream EngineBETA

HomePricingDocumentation

Security

Last Updated: October 2025

At Dream Engine, security is fundamental to everything we do. We employ industry-leading security practices to protect your data, content, and privacy. This page outlines our comprehensive security measures and practices.

Data Encryption

All data is encrypted both in transit and at rest:

  • TLS 1.3: All connections use the latest encryption protocols
  • AES-256: Data at rest is encrypted using industry-standard encryption
  • End-to-End: Your content remains encrypted throughout our infrastructure
  • Key Management: Encryption keys are securely managed and rotated regularly

Authentication & Access Control

We implement robust authentication and authorization measures:

  • Secure Authentication: Powered by Supabase Auth with industry-standard protocols
  • Password Security: Passwords are hashed using bcrypt with strong salting
  • Session Management: Secure token-based sessions with automatic expiration
  • Role-Based Access: Granular permissions ensure users only access their own data
  • Admin Controls: Separate admin authentication with enhanced security

Infrastructure Security

Our infrastructure is built on secure, enterprise-grade platforms:

  • Supabase: Database and storage with SOC 2 Type II compliance
  • Deno Deploy: Serverless functions with built-in security isolation
  • CDN Protection: DDoS protection and edge caching for content delivery
  • Regular Updates: Infrastructure automatically updated with security patches
  • Geographic Redundancy: Data replicated across multiple regions

Monitoring & Threat Detection

We continuously monitor for security threats:

  • 24/7 Monitoring: Real-time security monitoring and alerting
  • Anomaly Detection: AI-powered detection of unusual access patterns
  • Audit Logs: Comprehensive logging of all system activities
  • Incident Response: Dedicated team ready to respond to security incidents
  • Vulnerability Scanning: Regular automated security assessments

Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store your complete credit card information on our servers. Stripe employs advanced fraud detection and prevention measures to protect your financial data.

Third-Party Security

We carefully vet all third-party services we integrate with:

  • AI Providers: All external AI services meet strict security requirements
  • Data Minimization: We only share necessary data with third parties
  • Vendor Agreements: Security obligations defined in service agreements
  • Regular Audits: Periodic review of third-party security practices

Content Security

Your generated content is protected through multiple layers:

  • Isolated Storage: Each user's content is isolated and access-controlled
  • Secure URLs: Time-limited, signed URLs for content access
  • Deletion: Content can be permanently deleted upon request
  • Backup: Regular encrypted backups with secure retention policies

Security Best Practices for Users

Help us keep your account secure by following these recommendations:

  • Use a strong, unique password for your Dream Engine account
  • Never share your account credentials with others
  • Log out when using shared or public computers
  • Keep your email account secure (it's used for password recovery)
  • Report suspicious activity immediately
  • Review your account activity regularly

Compliance & Certifications

Dream Engine adheres to industry security standards and regulations:

  • GDPR Compliant: Full compliance with EU data protection regulations
  • CCPA Compliant: California Consumer Privacy Act compliance
  • SOC 2: Our infrastructure providers maintain SOC 2 Type II compliance
  • PCI DSS: Payment processing through PCI Level 1 certified providers

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please contact our security team immediately through our support channels. We commit to:

  • Respond to your report within 48 hours
  • Keep you informed of our progress
  • Credit you for the discovery (if you wish)
  • Not pursue legal action against responsible researchers

Security Updates

We continuously improve our security measures. This page is regularly updated to reflect our current practices. For the latest information or specific security questions, please visit our Documentation or contact our support team.

Security Commitment

Security is not a one-time effort but an ongoing commitment. We continuously invest in security infrastructure, training, and best practices to protect your data and maintain your trust.

Dream EngineDream Engine

Create stunning images, videos, music, and more with the power of AI.

Product

  • Features
  • Pricing
  • Changelog

Resources

  • Documentation
  • Tutorials
  • Community

Company

  • About Us
  • Careers
  • Contact

Legal

  • Privacy
  • Terms
  • Security

© 2026 Dream Engine. All rights reserved.

Privacy PolicyTerms of ServiceCookie Policy