Legal

Compliance

Last updated:

ModelsVault operates in the adult content industry and takes compliance seriously. This page outlines our obligations and the measures we take to ensure legal and ethical operation of the platform.

Age Verification

ModelsVault is strictly an 18+ platform. We enforce age verification at multiple levels:

  • Agency verification: All agency owners must submit government-issued photo ID (front and back) during registration. Accounts are manually reviewed and approved by our compliance team before activation.
  • Model onboarding: Agencies are contractually required to verify the age and identity of every model they manage before adding them to the platform.
  • Platform-level verification: The webcam platforms integrated with ModelsVault (Stripchat, OnlyFans, Cam4, LiveJasmin, etc.) each maintain their own independent age verification processes.

Any account found to be associated with underage individuals will be immediately terminated and reported to the relevant authorities.

Record-Keeping (2257 / AVMS)

ModelsVault is a management and analytics platform — we do not host, produce, or distribute adult content. Content is hosted and distributed by the integrated third-party platforms.

Agencies using ModelsVault remain solely responsible for maintaining all required records under applicable regulations, including:

  • US 18 U.S.C. § 2257: If you operate in or serve US-based platforms, you must maintain performer records as required by 18 U.S.C. § 2257 and 28 C.F.R. Part 75.
  • EU Audiovisual Media Services Directive (AVMSD): EU-based agencies must comply with applicable national implementations of the AVMSD.
  • UK Online Safety Act: UK-based operators must comply with age assurance and content moderation obligations under the Online Safety Act 2023.

ModelsVault stores identity documents submitted during agency verification for the minimum period required by applicable law. These records are available to authorised regulatory bodies upon lawful request.

GDPR and Data Protection

ModelsVault processes personal data in accordance with the UK GDPR and EU GDPR. Our full data practices are described in our Privacy Policy.

  • We process data only for specified, explicit, and legitimate purposes
  • We do not sell personal data to third parties
  • We implement data minimisation — we collect only what is necessary
  • Data subjects can exercise their rights (access, erasure, portability) by contacting us
  • We maintain records of processing activities as required by Article 30 GDPR
  • We have a data breach notification procedure in place (72-hour notification to supervisory authority)

Data Security

We implement the following technical and organisational security measures:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for sensitive credentials and documents at rest
  • bcrypt password hashing with appropriate cost factor
  • Role-based access controls — agency owners can only access their own models' data
  • Session management with secure, HTTP-only cookies
  • Regular security reviews and vulnerability assessments
  • Audit logging for sensitive operations

Prohibited Content and Activities

ModelsVault has a zero-tolerance policy for the following. Any account found to be involved in these activities will be immediately terminated and reported to law enforcement:

  • Any content involving minors (persons under 18) in a sexual context
  • Non-consensual content or content produced under coercion
  • Human trafficking or exploitation of any kind
  • Fraudulent earnings manipulation or platform abuse
  • Money laundering or use of the platform for illegal financial activity

If you become aware of any such activity on the platform, report it immediately to [email protected] or contact the relevant national authority (e.g., the Internet Watch Foundation in the UK, NCMEC in the US).

Payment Compliance (PCI DSS)

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. ModelsVault does not store, process, or transmit cardholder data. Our payment integration is designed to ensure we remain out of scope for PCI DSS requirements.

Subscription billing, invoicing, and payment method management are handled entirely within Stripe's secure environment.

Compliance Contact

For compliance enquiries, regulatory requests, or to report a concern, contact our compliance team:

[email protected]