Security Architecture & Trust
Engineering controls, cryptographic verification layers, and cloud infrastructure safeguards that protect Credinberg digital credentials globally.
Infrastructure & Cloud Perimeter
Credinberg operates an enterprise cloud environment designed for high availability, zero-trust access, and multi-region resilience:
- Distributed Edge Compute: Cryptographic verification and web delivery operate on an enterprise edge network, ensuring low-latency access and rapid response times worldwide.
- Managed Database Layer: Production databases are hosted in isolated virtual private networks with strict network-level access controls, automated connection pooling, and zero direct public access to database ports.
- Encrypted Object Storage: Issued badge media and credential assets are stored immutably with multi-region redundancy and continuous encryption at rest.
Tenant Isolation & Access Control
Protecting customer data boundaries is fundamental to our platform design. Credinberg enforces data separation natively at the database engine level using strict row-level security controls:
- Engine-Enforced Data Scoping: Every query executed by an authenticated user is scoped strictly to their verified organization membership, making cross-organization data access impossible at the database level.
- Least-Privilege API Routing: All internal services operate under strict least-privilege service roles with scoped tokens, eliminating blanket administrative privileges.
- Auditability: Organizational changes, credential issuance operations, and team member role modifications are logged for security oversight.
Encryption in Transit & At Rest
All data traveling between users, verifiers, and backend infrastructure is protected using modern cryptographic standards:
- TLS 1.3 in Transit: All web and API traffic enforces HTTPS with TLS 1.3 and HTTP Strict Transport Security (HSTS). Unencrypted or outdated protocols are automatically rejected.
- AES-256 Encryption At Rest: Database volumes, file assets, and backup archives are encrypted at rest using industry-standard AES-256 encryption.
- Secure Credential Storage: Authentication credentials and passwords undergo cryptographic salted hashing. API secrets and integration tokens are securely stored in runtime secret management vaults.
Open Badges & Cryptographic Signatures
Every credential issued on Credinberg adheres to the open Open Badges 2.0 / 3.0 Specification and the W3C Verifiable Credentials Data Model:
- Cryptographic Digital Signatures: Every issued credential includes cryptographically calculated verification proofs and assertion metadata, enabling instant mathematical validation against the issuer's public verification URL.
- Tamper-Evident Image Baking: The complete JSON-LD assertion and signature payload are cryptographically baked into badge image metadata. Any modification to image pixels or credential metadata breaks the digital signature.
- Universal Interoperability: Credinberg credentials can be uploaded and verified on standard Open Badges validators, digital credential wallets, and enterprise verification platforms worldwide.
Access Governance & Authentication Controls
We enforce comprehensive authentication safeguards and granular authorization controls across all account tiers:
- DNS-Based Domain Ownership Verification: Issuing organizations must prove administrative authority over their official web domain via cryptographic DNS TXT record validation before publishing verified credentials.
- Verification via One-Time Passwords (OTP): Enforces secure email verification codes for account onboarding, email linking, and sensitive password updates.
- Brute-Force Protection: Automated rate limiting and lockout safeguards protect accounts against credential stuffing and brute-force attacks.
- Role-Based Access Control (RBAC): Granular permissions within workspaces: Owner, Admin, Issuer, and Viewer roles ensure team members access only what their function requires.
- Session Management: Sessions use short-lived secure tokens. User sign-out immediately revokes the active session token.
Application & Network Defense
Credinberg deploys defense-in-depth security controls to guard against volumetric attacks and common web vulnerabilities:
- DDoS & Web Application Protection: Edge proxy layers filter and mitigate distributed denial-of-service (DDoS) attacks before traffic reaches backend servers.
- Abuse & Bot Prevention: Automated rate-limiting and threat detection block abusive scrapers and unauthorized automated scripts.
- Security Headers: Core dashboard, passport, and authentication routes enforce Content Security Policy (CSP) and frame-ancestor protections to prevent clickjacking and unauthorized embeds.
- Parameterized Queries: Database queries are executed strictly through parameterized statements, preventing SQL injection vulnerabilities.
Business Continuity & Backups
To ensure uninterrupted service and data durability, Credinberg maintains multi-tier recovery safeguards:
- Automated Backups: Continuous write-ahead backups and snapshot copies are maintained across geographically separated locations to prevent data loss.
- Disaster Recovery Testing: Infrastructure as code allows rapid environment recovery and point-in-time restoration in emergency scenarios.
Authorized Subprocessors & Vendor Due Diligence
Credinberg partners strictly with enterprise infrastructure and cloud providers that hold certified security standards (SOC 2 Type II, ISO/IEC 27001) and maintain strict Data Processing Addendums (DPAs) with Standard Contractual Clauses (SCCs):
| Subprocessor | Service Scope | Data Location | Security Certifications |
|---|---|---|---|
| Supabase, Inc. (AWS) | Primary database hosting, row-level tenant isolation & auth vaults | United States | SOC 2 Type II, ISO 27001 |
| Cloudflare, Inc. | Global Edge WAF, encrypted R2 object storage & DDoS protection | Global Edge Network | SOC 2 Type II, PCI-DSS |
| Vercel, Inc. | Edge application compute runtime & cryptographic SSR rendering | Global Edge | SOC 2 Type II, ISO 27001 |
| Resend, Inc. | Transactional security alerts, OTP verifications & claim emails | United States | SOC 2 Type II |
| PostHog, Inc. | Product telemetry & retention metrics (session recording disabled) | United States / EU | SOC 2 Type II, EU-US DPF |
| Microsoft Corporation | Microsoft Clarity UX telemetry with automated PII masking | United States | ISO 27001, SOC 2 Type II |
| Google LLC | Google Tag Manager telemetry containerization | United States | ISO 27001, SOC 2 Type II |
| Stripe, Inc. | Subscription billing settlement & encrypted merchant processing | United States | PCI-DSS Level 1 |
Responsible Vulnerability Disclosure
We value the vital contribution of independent security researchers. If you identify a potential security vulnerability within Credinberg systems:
- Submit reports directly to security@credinberg.com with reproducible steps.
- Provide reasonable time for our engineering team to investigate and remediate before public disclosure.
- Do not degrade platform availability, execute volumetric denial-of-service, or compromise customer privacy.
Terms of Service
Review customer intellectual property rights, acceptable credential issuance policies, and enterprise service guarantees.
Credinberg Global Governance & Compliance Office
Authoritative legal and privacy policy repository. Inquiries may be directed to legal@credinberg.com.