Auric Artisan · Trust & Security
Security at Auric Artisan
We protect your data with a multi-layered defense-in-depth architecture. Every request passes through a 9-step security pipeline before it ever reaches a route handler.
Defense-in-Depth Architecture
Our security subsystem is organised into three tiers that work together to detect and neutralise threats - from automated bots to credential stuffing to payment abuse.
A 9-step pipeline processes every incoming request. Rate limiting, CSRF protection, request validation, session guards, and abuse detection run before any route handler executes.
Pattern-based analysis with escalating automated countermeasures. Threats are scored and handled progressively: throttle -> challenge -> block.
An invisible behavioral analysis system that scores users without interactive challenges. Mouse movements, keyboard cadence, and session timing are analysed in real time.
HMAC token generation on the client, API key + signature verification on the server, and continuous token revalidation with IP-based rate limiting.
Request Security Pipeline
Every request to the Auric Artisan platform passes through this pipeline sequentially. If any step fails, the request is rejected before it reaches the application layer.
Rate Limiting
KV-backed sliding window rate limiter prevents abuse. Limits are per-IP, per-route, and per-user with configurable thresholds.
CSRF Protection
Double-submit cookie + header validation ensures requests originate from legitimate browser sessions.
Request Validation
Schema validation and injection scanning. Every request body, query parameter and header is validated against strict schemas.
Session Integrity
Session guard verifies integrity, performs automatic rotation, and detects anomalies like session fixation or hijacking attempts.
Token Verification
Server-side API key and HMAC signature verification with continuous revalidation throughout the request lifecycle.
Bot Scoring
Composite bot scoring engine analyses behavioral signals from mouse, keyboard, and timing trackers to compute a bot probability score.
Abuse Analysis
Multi-signal abuse analysis detects credential stuffing, payment fraud, scraping, and other malicious patterns.
Countermeasure Escalation
Automated countermeasures escalate proportionally: soft throttle -> visual challenge -> temporary block -> permanent ban.
Security Logging
Structured security event logging records every decision, enriched with request metadata for audit and incident response.
Encryption & Data Protection
Your data is encrypted at every layer - in transit, at rest, and within backups.
All connections use TLS 1.3 with HSTS enforcement. Certificates are automatically provisioned and rotated.
Stored data is encrypted at rest by Cloudflare across D1, R2 and KV. We do not operate our own storage layer, so there is no unencrypted copy on a machine we manage.
API keys, signing secrets and database credentials live in Cloudflare's encrypted secret store. Once set, no one can read a value back — including us. None exist in our source code.
Two-factor secrets are encrypted before storage under a key held only as a deployment secret, so a database copy alone cannot generate anyone's codes.
Authentication & Access Control
We implement strict authentication controls with multiple layers of identity verification.
Passwords are hashed at the OWASP-recommended work factor. Your password is never stored, never logged, and cannot be recovered by us — a reset replaces it rather than revealing it.
Only a SHA-256 hash of each API key is kept, plus a short prefix so keys can be told apart. The key itself is shown once at creation and never again — lose it and you rotate it.
TOTP-based two-factor authentication with backup codes. Device trust management remembers verified devices securely.
Integrate with trusted OAuth providers for SSO. All OAuth flows use PKCE and state validation to prevent interception.
Track and manage trusted devices. Suspicious login from a new device triggers additional verification or alerts.
Sessions rotate automatically, expire on inactivity, and enforce a maximum session lifetime. Sessions can be revoked remotely.
Infrastructure Security
The platform is deployed on Cloudflare's global edge network with strict security headers and isolation.
Deployed on Cloudflare Workers at 300+ locations worldwide. DDoS protection, WAF, and bot management run at the edge before traffic reaches origin.
Strict Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers on every response.
HTTP Strict Transport Security (HSTS) is enabled with a max-age of one year and is submitted for browser preload lists.
Each worker runs in an isolated V8 sandbox with no shared memory or filesystem access between requests.
Payments
Card details never reach our servers. The parts of a payment we do control are designed so that the browser cannot influence what you are charged.
Payments are processed by Razorpay, a PCI-DSS compliant gateway. Your card number is entered into Razorpay's own checkout and is never transmitted to, stored by, or visible to us. We receive a payment reference and its status, nothing more.
The amount charged is resolved from our own catalogue when the order is created, not taken from the page. A modified browser cannot change what a purchase costs.
Every payment notification is verified against a signing secret before it can affect an account, and fulfilment is idempotent — a notification delivered twice grants an entitlement once.
Account erasure anonymises personal data in place rather than destroying financial records. Tax law requires invoices to be retained, and an invoice naming nobody is not a valid record — so the transaction remains and your identity does not.
What We Do Not Claim
A security page listing only strengths is marketing. These are the limits, stated plainly, so you can judge whether Auric Artisan fits your requirements.
We are not SOC 2, ISO 27001 or HIPAA certified. If your organisation requires a certified vendor, we are not one today.
The measures described here are implemented and tested by us. They have not been audited by an independent third party.
Fixes ship quickly and without bureaucracy. There is also no 24/7 on-call rotation, and no separation of duties — response times are best-effort.
Email is delivered through Resend, payments through Razorpay, hosting and storage through Cloudflare. Their security practices are their own, not ours.
Responsible Disclosure
We welcome responsible security researchers and take every report seriously. If you discover a vulnerability, please report it through our disclosure process.
How to Report a Vulnerability
Send a detailed report to [email protected] with a description of the vulnerability, steps to reproduce, and any proof of concept. Please do not publicly disclose the issue until we have had time to investigate and patch.
If you would rather not use email, the contact form routes security reports here too — it opens with the right queue selected.
We aim to acknowledge receipt within 24 hours, provide an initial assessment within 72 hours, and resolve confirmed vulnerabilities within 30 days.
Researchers acting in good faith will never face legal action. We are committed to treating security researchers as partners in keeping the platform safe.