90 Days Gen AI Risk Trial -Start Now
Book a demo
Video·Free; Hobbyist $16/mo; Creator $24/mo; Business $50/mo; Enterprise custom·descript.com

Descript

Descript edits audio and video by editing the transcript, with AI tools for filler-word removal, dubbing, and Overdub voice cloning for podcasts and video content.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Descript is an all-in-one audio and video editor where edits happen in a text transcript rather than on a waveform or timeline. Its Underlord AI co-editor automates common tasks — filler-word removal, multi-cam switching, captions, eye contact correction, and AI dubbing into 30+ languages. It is widely used by podcasters, YouTubers, and internal comms teams. The Overdub feature clones a speaker's voice from a 10+ minute sample, gated by a verbal consent statement that is matched against the uploaded audio. Descript prohibits cloning non-consenting third-party voices in its terms. Descript is SOC 2 Type II certified and aligns with GDPR and CCPA, but does not publish HIPAA compliance. AI features such as transcription require opt-in to share data for service improvement; project files are retained 30 days after deletion.

Risk factors

3
  • Cloud SaaS with potential third-party data access
  • User-generated content for audio/video editing
  • Requires user-uploaded media for functionality

Recommendations

8
  • Require Business or Enterprise plan with SSO/SCIM for workforce deployments
  • Disable Overdub for general users; restrict to a reviewed list of creators
  • Require documented, recorded consent from every speaker whose voice is cloned
  • Turn off data sharing for AI improvement across the workspace
  • Forbid uploading PHI, customer support calls, or regulated recordings without legal review
  • Use watermarks or visible disclosures when publishing AI-dubbed or voice-cloned output
  • Enforce private-by-default sharing and review public link policy
  • Review SOC 2 Type II report and DPA via the Descript trust page

Data handling

Storage
Projects stored encrypted (AES-256) on AWS and Google Cloud; TLS 1.2+ in transit. Third-party subprocessors include Rev/Whisper for transcription and Stripe for billing.
Retention
Deleted projects purged within 30 days; account deletion removes associated data. Export and portability available on request.
Training on inputs
Transcription and AI improvement data sharing is opt-in. Overdub voice models are tenant-scoped and gated by a matched verbal consent statement; third-party voice cloning is prohibited by terms.