Best-Edit is a multi-tenant editorial and newsroom service. This page describes safeguards visible in the current product and the service providers used to operate particular features. It does not claim that Best-Edit has completed an independent security certification or audit.
Security Controls
- Account passwords are stored as salted scrypt hashes. Best-Edit does not store plaintext account passwords.
- Production sessions require a configured session secret. Session cookies are marked Secure in production, HttpOnly, and SameSite=Lax, with a 30-day maximum age.
- Product access is restricted through account, role, permission, team, publication, feature-grant, and edition controls, depending on the feature.
- Stored third-party credentials use AES-256-GCM encryption. Best-Edit API keys are displayed once and stored as a prefix and salted scrypt hash rather than as the complete key.
- Error monitoring disables default transmission of personally identifiable information and applies rules intended to remove credentials, cookies, prompts, drafts, transcripts, and other sensitive fields. Session replay is disabled.
- Newsroom and Civic share infrastructure but apply edition-specific controls to prompts, feature resolution, and reference retrieval. Civic reference content does not fall back to Newsroom reference content.
Data Lifecycle
Best-Edit keeps account information and customer content while the relevant account or organization is active and as needed for the service, provenance, audit, security, contractual, and legal purposes. Temporary upload records generally expire within minutes to 24 hours. Live-transcription audio is scheduled for deletion after 30 days, while resulting transcripts may remain as customer content.
Product deletion can remove content from active views before every associated database, audit, provider, or backup record is erased. Best-Edit does not currently offer self-service account deletion. See the Privacy Policy for request instructions and additional retention details.
Subprocessors & Service Providers
The providers below support the service or particular optional features. The data sent to a provider depends on the feature a customer enables and the action an authorized user requests. Customer-selected publishing destinations and connected accounts, such as WordPress, Meta, X, Slack, Mailchimp, Arc XP, Naviga, and customer webhooks, are not listed as Best-Edit subprocessors solely because Best-Edit sends data to them at a customer's direction.
Replit
- Purpose
- Application hosting, runtime infrastructure, and object storage
- Information Processed
- Customer content, account information, encrypted credentials, files, recordings, and operational metadata
- When Used
- Core service and features that store files
Neon
- Purpose
- Managed PostgreSQL database infrastructure
- Information Processed
- Account records, customer content, workflow records, integration metadata, and audit and usage records
- When Used
- Core service
Anthropic
- Purpose
- Generative AI inference and related AI operations
- Information Processed
- Prompts, instructions, selected customer content and context, generated output, and technical request metadata
- When Used
- AI-enabled features
ElevenLabs
- Purpose
- Audio and media transcription
- Information Processed
- Audio, media URLs, transcription settings, transcripts, speaker information, and technical metadata
- When Used
- Transcription features
Sentry
- Purpose
- Error, tracing, and performance monitoring
- Information Processed
- Scrubbed error and request context and technical identifiers; personal data may be included if a field is not recognized by the scrubbing rules
- When Used
- Core service monitoring
PostHog
- Purpose
- Product analytics
- Information Processed
- Account identifiers, organization attributes, page views, feature interactions, and operational measurements
- When Used
- When analytics is configured
Twilio
- Purpose
- Calling, SMS delivery, recording retrieval, and delivery callbacks
- Information Processed
- Phone numbers, message and call metadata, message content, consent and opt-out activity, recordings, and related identifiers
- When Used
- NewsHound, Interview, and Legman features
Apify
- Purpose
- Scheduled collection of configured source data
- Information Processed
- Source URLs, collection parameters, retrieved source material, and technical metadata
- When Used
- Pump Patrol
Letterhead
- Purpose
- Newsletter composition and publishing
- Information Processed
- Newsletter content, images, destination or segment identifiers, and delivery metadata
- When Used
- Newsletter features
Google Workspace / Gmail
- Purpose
- Account, invitation, password-reset, and service email
- Information Processed
- Recipient email address, account or invitation metadata, and service-message content
- When Used
- Account administration and enabled email workflows
Stripe
- Purpose
- Subscription billing and payment processing
- Information Processed
- Customer and subscription identifiers, payment status, invoices, and transaction metadata; Stripe collects complete payment-card details directly
- When Used
- Paid plans
Best-Edit uses a locally hosted BGE model for reference embeddings. The model does not itself create a third-party subprocessor relationship; the infrastructure on which it runs is covered by the relevant hosting provider above.
Best-Edit may update this list as the service changes. The date at the top of this page identifies the current version. Any contractual notice or objection rights are governed by the applicable customer agreement.
Report a Security Issue
To report a suspected vulnerability, unauthorized access, or other security issue, email security@monumentalstories.com and include a way for us to reach you. Do not include passwords, access tokens, private source material, or other sensitive customer content in the initial report.