Auric Artisan · Trust & Security

Security at Auric Artisan

We protect your data with a multi-layered defense-in-depth architecture. Every request passes through a 9-step security pipeline before it ever reaches a route handler.

Encrypted Transport Behavioral CAPTCHA Zero Trust
256-bit
AES Encryption
9-step
Security Pipeline
20+
Security Modules
3-tier
Defense Model
01

Defense-in-Depth Architecture

Our security subsystem is organised into three tiers that work together to detect and neutralise threats - from automated bots to credential stuffing to payment abuse.

MW Server-Side Middleware

A 9-step pipeline processes every incoming request. Rate limiting, CSRF protection, request validation, session guards, and abuse detection run before any route handler executes.

AD Abuse Detection & Response

Pattern-based analysis with escalating automated countermeasures. Threats are scored and handled progressively: throttle -> challenge -> block.

BC Behavioral CAPTCHA

An invisible behavioral analysis system that scores users without interactive challenges. Mouse movements, keyboard cadence, and session timing are analysed in real time.

TK Token & Verification

HMAC token generation on the client, API key + signature verification on the server, and continuous token revalidation with IP-based rate limiting.

02

Request Security Pipeline

Every request to the Auric Artisan platform passes through this pipeline sequentially. If any step fails, the request is rejected before it reaches the application layer.

01

Rate Limiting

KV-backed sliding window rate limiter prevents abuse. Limits are per-IP, per-route, and per-user with configurable thresholds.

02

CSRF Protection

Double-submit cookie + header validation ensures requests originate from legitimate browser sessions.

03

Request Validation

Schema validation and injection scanning. Every request body, query parameter and header is validated against strict schemas.

04

Session Integrity

Session guard verifies integrity, performs automatic rotation, and detects anomalies like session fixation or hijacking attempts.

05

Token Verification

Server-side API key and HMAC signature verification with continuous revalidation throughout the request lifecycle.

06

Bot Scoring

Composite bot scoring engine analyses behavioral signals from mouse, keyboard, and timing trackers to compute a bot probability score.

07

Abuse Analysis

Multi-signal abuse analysis detects credential stuffing, payment fraud, scraping, and other malicious patterns.

08

Countermeasure Escalation

Automated countermeasures escalate proportionally: soft throttle -> visual challenge -> temporary block -> permanent ban.

09

Security Logging

Structured security event logging records every decision, enriched with request metadata for audit and incident response.

03

Encryption & Data Protection

Your data is encrypted at every layer - in transit, at rest, and within backups.

TLS TLS 1.3 in Transit

All connections use TLS 1.3 with HSTS enforcement. Certificates are automatically provisioned and rotated.

AES Encrypted at Rest

Stored data is encrypted at rest by Cloudflare across D1, R2 and KV. We do not operate our own storage layer, so there is no unencrypted copy on a machine we manage.

SEC Write-Only Secrets

API keys, signing secrets and database credentials live in Cloudflare's encrypted secret store. Once set, no one can read a value back — including us. None exist in our source code.

2FA Encrypted TOTP Seeds

Two-factor secrets are encrypted before storage under a key held only as a deployment secret, so a database copy alone cannot generate anyone's codes.

04

Authentication & Access Control

We implement strict authentication controls with multiple layers of identity verification.

PBK PBKDF2-SHA256, 600,000 Iterations

Passwords are hashed at the OWASP-recommended work factor. Your password is never stored, never logged, and cannot be recovered by us — a reset replaces it rather than revealing it.

KEY API Keys Stored as Hashes

Only a SHA-256 hash of each API key is kept, plus a short prefix so keys can be told apart. The key itself is shown once at creation and never again — lose it and you rotate it.

2FA Multi-Factor Authentication

TOTP-based two-factor authentication with backup codes. Device trust management remembers verified devices securely.

OA OAuth Providers

Integrate with trusted OAuth providers for SSO. All OAuth flows use PKCE and state validation to prevent interception.

DV Device Management

Track and manage trusted devices. Suspicious login from a new device triggers additional verification or alerts.

SS Session Management

Sessions rotate automatically, expire on inactivity, and enforce a maximum session lifetime. Sessions can be revoked remotely.

05

Infrastructure Security

The platform is deployed on Cloudflare's global edge network with strict security headers and isolation.

ED Edge-First Deployment

Deployed on Cloudflare Workers at 300+ locations worldwide. DDoS protection, WAF, and bot management run at the edge before traffic reaches origin.

HD Security Headers

Strict Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers on every response.

HS HSTS Preloaded

HTTP Strict Transport Security (HSTS) is enabled with a max-age of one year and is submitted for browser preload lists.

IS Isolation & Sandboxing

Each worker runs in an isolated V8 sandbox with no shared memory or filesystem access between requests.

06

Payments

Card details never reach our servers. The parts of a payment we do control are designed so that the browser cannot influence what you are charged.

PCI Cards Never Touch Us

Payments are processed by Razorpay, a PCI-DSS compliant gateway. Your card number is entered into Razorpay's own checkout and is never transmitted to, stored by, or visible to us. We receive a payment reference and its status, nothing more.

AMT Server-Priced Orders

The amount charged is resolved from our own catalogue when the order is created, not taken from the page. A modified browser cannot change what a purchase costs.

SIG Signed Webhooks

Every payment notification is verified against a signing secret before it can affect an account, and fulfilment is idempotent — a notification delivered twice grants an entitlement once.

ERA Erasure Without Data Loss

Account erasure anonymises personal data in place rather than destroying financial records. Tax law requires invoices to be retained, and an invoice naming nobody is not a valid record — so the transaction remains and your identity does not.

07

What We Do Not Claim

A security page listing only strengths is marketing. These are the limits, stated plainly, so you can judge whether Auric Artisan fits your requirements.

CRT No Formal Certification

We are not SOC 2, ISO 27001 or HIPAA certified. If your organisation requires a certified vendor, we are not one today.

PEN No External Penetration Test

The measures described here are implemented and tested by us. They have not been audited by an independent third party.

OPS Operated by One Person

Fixes ship quickly and without bureaucracy. There is also no 24/7 on-call rotation, and no separation of duties — response times are best-effort.

3P Third-Party Dependencies

Email is delivered through Resend, payments through Razorpay, hosting and storage through Cloudflare. Their security practices are their own, not ours.

08

Responsible Disclosure

We welcome responsible security researchers and take every report seriously. If you discover a vulnerability, please report it through our disclosure process.

How to Report a Vulnerability

Send a detailed report to [email protected] with a description of the vulnerability, steps to reproduce, and any proof of concept. Please do not publicly disclose the issue until we have had time to investigate and patch.

If you would rather not use email, the contact form routes security reports here too — it opens with the right queue selected.

We aim to acknowledge receipt within 24 hours, provide an initial assessment within 72 hours, and resolve confirmed vulnerabilities within 30 days.

Researchers acting in good faith will never face legal action. We are committed to treating security researchers as partners in keeping the platform safe.