STAR Registry Listing for
TranscriptFetch API
TranscriptFetch API
The TranscriptFetch API converts video and web content into structured text for AI systems and data pipelines. One REST endpoint accepts a URL from YouTube, TikTok, Instagram, X or Facebook, or a direct media file, and returns the transcript as timestamped JSON. Other endpoints resolve YouTube channels, playlists and searches into video lists, batch up to 50 videos per request, and return any web page as clean Markdown. When a video has no caption track, the audio is transcribed automatically.
The service is HTTPS only. Requests authenticate with a per-account bearer token, generated from a cryptographically secure source and stored only as a SHA-256 hash, so a database disclosure exposes no usable credential and a token cannot be redisplayed after creation. Tokens are individually revocable with immediate effect. No CORS headers are returned, by design, so credentials cannot be embedded in browser-side code. Requests are rate limited per token.
Scope of assessment: a single-product SaaS API on managed infrastructure, namely Neon (Postgres), Clerk (authentication), Stripe (payments), Cloudflare (DNS, CDN, TLS), Groq (speech recognition) and Resend (email). The application origin is not reachable from the public internet; it is served through an outbound Cloudflare tunnel. No datacenters, physical facilities, customer-managed virtualization or corporate endpoints are operated.
Security documentation: https://transcriptfetch.com/security

Listed Since: 07/27/2026
STAR Level 1

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 1 day ago, on July 27, 2026.