NEWS
Verax AI Risk Assessment is live. See what's exposed
Hedra
Hedra
 
Risk Overview
Moderate Risk
4.6
/10
Video Generation
·
Avatar Generation
·
Audio Generation
·
Top Risks

Mandatory arbitration with $100 liability cap (extremely low). Class action and jury trial waiver. Biometric data collection (facial geometry) raises regulatory risk under BIPA and similar laws. Broad perpetual irrevocable license to user content. SOC 2 certification status uncertain. No GDPR compliance confirmation.

Mitigations

Opt out of arbitration clause within 30 days of account creation. Verify SOC 2 status before enterprise deployment. Biometric data auto-deletion within 24 hours is mitigating. Do not upload faces of individuals without consent. Avoid storing sensitive content long-term. Request enterprise DPA.

Get started
Is your team using 
Hedra
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

Section 14 contains MANDATORY BINDING ARBITRATION AND CLASS ACTION WAIVER in all-caps. Jury trial waiver explicitly stated. Liability cap: greater of fees paid in prior 3 months or $100 — very low cap ($100 floor). Governing law: New York. 30-day opt-out window for arbitration clause available. These are highly restrictive legal terms.
8
/10

Training Use

Hedra grants itself a broad license to use Your Content (inputs and outputs) for 'operating and providing the Service to you and to our other users.' License is non-exclusive, transferable, perpetual, irrevocable, worldwide, fully-paid, royalty-free, sublicensable. This broad license likely covers training. Biometric data (facial geometry) collected only for animation, not identity verification, deleted within 24 hours. No explicit training opt-out mentioned.
5
/10

Security Posture

SOC 2 Type II certification was 'in progress' with Q1 2025 target as of last known status — unclear if achieved. Uses SOC 2 compliant cloud hosting providers. Biometric data handled with explicit legal compliance framework (BIPA/state laws). No public ISO 27001 certification. No bug bounty program mentioned. Biometric data deletion within 24 hours is a strong security practice.
5
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.