90 Days Gen AI Risk Trial -Start Now
Book a demo
Video·Free (3 videos/mo); Creator $24/mo; Pro $99/mo; Business $149/mo; Enterprise custom·app.heygen.com

HeyGen

HeyGen creates avatar-led videos from text, clones voices, and lip-syncs translations across languages, targeting marketers, creators, and enterprise teams.

Risk Score
High
6/10

Independent assessment across data handling, compliance, security and transparency.

Overview

HeyGen is an AI video generation platform focused on avatar creation, instant video translation with lip-sync, and personalized video at scale. It is popular for outbound sales, localized marketing, product onboarding, and creator content, with a lower price point than Synthesia and heavier self-serve adoption. HeyGen is SOC 2 Type II, GDPR, CCPA, and EU AI Act aligned, and requires consent verification for custom avatars to combat deepfake misuse. However, the tool's accessibility and cheap personal-avatar tier make unauthorized-likeness abuse a real concern, and the standard plans keep less rigorous controls than enterprise. Governance teams should treat uploaded faces, voices, and scripts as regulated biometric and business data.

Risk factors

3
  • User data may be used for training without clear opt-out options
  • Potential for sensitive data exposure through avatar creation
  • No SSO or enterprise-level security features

Recommendations

8
  • Require the Business or Enterprise plan with SSO for any team deployment
  • Mandate signed consent for every custom avatar, retained with an audit trail
  • Prohibit cloning executives, customers, or public figures without release
  • Treat personalized-video prospect data as PII; honor deletion requests
  • Review HeyGen's DPA and Acceptable Use Policy before rollout
  • Disable or watermark public video sharing from corporate accounts
  • Log API key issuance and rotate regularly; restrict to known use cases
  • Train sales and marketing on deepfake and likeness-rights obligations

Data handling

Storage
Cloud-hosted (AWS) with encryption at rest and in transit; enterprise tenants can request regional controls
Retention
Assets retained while subscription is active; deletion on request per privacy policy and DPA
Training on inputs
Customer videos, scripts, and custom avatars are not used to train general models; consent required for likeness and voice capture