Security is foundational to how Clone13 is built. Salespeople trust us with their photo and voice; dealerships trust us with their customer relationships. Here is how we protect both.
Last updated: October 2026
Every account is issued by invitation and tied to a verified email address. Passwords are never stored in readable form, and a dealership administrator can deactivate a person's access the moment they leave the rooftop.
Dealership accounts sign in with email and password only — no third-party social sign-in. Sessions are issued by our authentication service and revalidated on the server for every protected request, so a stored browser flag can never open a workspace.
Photos, voice samples, scripts and generated videos are encrypted in transit with TLS and encrypted at rest in our cloud storage. Access to production data is restricted to a small number of engineers under least-privilege, time-bound and logged access.
Videos are delivered over private, unguessable short links rather than public listings, and the delivery domain is excluded from search engines. Generated videos and the media behind them are retained only while the dealership's account is active.
Each dealership is a logically isolated tenant. Photos, voices, templates and videos are scoped to the dealership and to the salesperson who owns them, and nothing crosses a dealership boundary. Roles inside a rooftop each see only what their work requires.
Clone13 runs on hardened, managed cloud infrastructure with automatic patching, network isolation and continuous monitoring. Media is served from dedicated object storage with signed access rather than from publicly browsable buckets.
We collect only what is needed to produce and deliver a video: the salesperson's photo, voice sample and script, plus the customer's name and vehicle details. We do not sell personal data and we do not use customer information for advertising.
AI likeness and voice cloning is biometric processing. It requires the salesperson's signed consent, captured in-app with a timestamped record. Consent can be withdrawn at any time — the likeness is taken out of use at once and the photo, voice model and videos made with it are destroyed.
We monitor for abuse and security incidents continuously and investigate every credible report. Security researchers, dealerships and individuals can reach us at any hour through our contact page, and we acknowledge reports within one business day.
If you believe you have found a vulnerability, or you need to report misuse of a likeness, contact us with the subject “Security Report.” We work with researchers in good faith and will never pursue action against someone who reports an issue responsibly.
Clone13, LLC · 333 N Michigan Avenue #616, Chicago, IL 60601