Security & Vault Architecture
When clients provide API keys, database credentials, and proprietary brand assets, security is not an add-on: it is the fundamental core of our infrastructure.
1. Core Security Principles
Client-Side Encryption
Secrets are encrypted in the client browser before network transmission. Plaintext never hits logs.
Edge Infrastructure
Powered by Cloudflare Workers and Enterprise CDN with automated DDoS mitigation and WAF rules.
Tenant Data Isolation
All client portal storage boundaries are strictly isolated with cryptographic access enforcement.
2. Cryptographic Specifications
3. Data Retention & Deletion Lifecycle
When a project portal is deleted by the agency, all associated files, metadata, and encrypted vault entries are permanently scheduled for purge.
- Active Portal Data: Stored during active collection period.
- Archived Portals: Read-only access retained for agency records with zero storage fees.
- Deleted Portals: Permanently wiped from R2 storage within 30 days.
- Disaster Recovery Snapshots: Encrypted at rest and purged every 90 days.
4. Responsible Vulnerability Disclosure
We welcome reports from independent security researchers and ethical hackers. If you discover a vulnerability in AssetSnag systems or APIs, please contact our security team directly.