Skip to main content
Permanent Free Plan Available•Paid plans from $19/moSee pricing
Zero-Knowledge Architecture

Security & Vault Architecture

When clients provide API keys, database credentials, and proprietary brand assets, security is not an add-on: it is the fundamental core of our infrastructure.

AES-256-GCM EncryptionTLS 1.3 in TransitCloudflare R2 at RestGDPR & DPA Compliant

1. Core Security Principles

Client-Side Encryption

Secrets are encrypted in the client browser before network transmission. Plaintext never hits logs.

Edge Infrastructure

Powered by Cloudflare Workers and Enterprise CDN with automated DDoS mitigation and WAF rules.

Tenant Data Isolation

All client portal storage boundaries are strictly isolated with cryptographic access enforcement.

2. Cryptographic Specifications

Data in Transit
Enforced strictly over TLS 1.3 and TLS 1.2 with HSTS enabled (HTTP Strict Transport Security, max-age 31536000). Automated certificate rotation managed at edge nodes.
Data at Rest
All uploaded files and deliverables are stored in Cloudflare R2 object storage with AES-256 server-side encryption. Database records are stored in Cloudflare D1 with disk-level encryption.
Credential Vault Cipher
Sensitive passwords and API keys use AES-256-GCM authenticated symmetric encryption. Encryption keys are generated per submission session and cannot be decrypted by AssetSnag infrastructure.
Magic Link Tokens
Client onboarding URLs utilize cryptographically secure, high-entropy 256-bit random tokens. Tokens can be expired on demand, auto-revoked upon portal completion, or set to timed expiration.

3. Data Retention & Deletion Lifecycle

When a project portal is deleted by the agency, all associated files, metadata, and encrypted vault entries are permanently scheduled for purge.

  • Active Portal Data: Stored during active collection period.
  • Archived Portals: Read-only access retained for agency records with zero storage fees.
  • Deleted Portals: Permanently wiped from R2 storage within 30 days.
  • Disaster Recovery Snapshots: Encrypted at rest and purged every 90 days.

4. Responsible Vulnerability Disclosure

We welcome reports from independent security researchers and ethical hackers. If you discover a vulnerability in AssetSnag systems or APIs, please contact our security team directly.

security@assetsnag.app
Submit Security Report