Security Architecture & Trust

Engineering controls, cryptographic verification layers, and cloud infrastructure safeguards that protect Credinberg digital credentials globally.

Effective: September 11, 2026·

Infrastructure & Cloud Perimeter

Credinberg operates an enterprise cloud environment designed for high availability, zero-trust access, and multi-region resilience:

  • Distributed Edge Compute: Cryptographic verification and web delivery operate on an enterprise edge network, ensuring low-latency access and rapid response times worldwide.
  • Managed Database Layer: Production databases are hosted in isolated virtual private networks with strict network-level access controls, automated connection pooling, and zero direct public access to database ports.
  • Encrypted Object Storage: Issued badge media and credential assets are stored immutably with multi-region redundancy and continuous encryption at rest.

Tenant Isolation & Access Control

Protecting customer data boundaries is fundamental to our platform design. Credinberg enforces data separation natively at the database engine level using strict row-level security controls:

  • Engine-Enforced Data Scoping: Every query executed by an authenticated user is scoped strictly to their verified organization membership, making cross-organization data access impossible at the database level.
  • Least-Privilege API Routing: All internal services operate under strict least-privilege service roles with scoped tokens, eliminating blanket administrative privileges.
  • Auditability: Organizational changes, credential issuance operations, and team member role modifications are logged for security oversight.

Encryption in Transit & At Rest

All data traveling between users, verifiers, and backend infrastructure is protected using modern cryptographic standards:

  • TLS 1.3 in Transit: All web and API traffic enforces HTTPS with TLS 1.3 and HTTP Strict Transport Security (HSTS). Unencrypted or outdated protocols are automatically rejected.
  • AES-256 Encryption At Rest: Database volumes, file assets, and backup archives are encrypted at rest using industry-standard AES-256 encryption.
  • Secure Credential Storage: Authentication credentials and passwords undergo cryptographic salted hashing. API secrets and integration tokens are securely stored in runtime secret management vaults.

Open Badges & Cryptographic Signatures

Every credential issued on Credinberg adheres to the open Open Badges 2.0 / 3.0 Specification and the W3C Verifiable Credentials Data Model:

  • Cryptographic Digital Signatures: Every issued credential includes cryptographically calculated verification proofs and assertion metadata, enabling instant mathematical validation against the issuer's public verification URL.
  • Tamper-Evident Image Baking: The complete JSON-LD assertion and signature payload are cryptographically baked into badge image metadata. Any modification to image pixels or credential metadata breaks the digital signature.
  • Universal Interoperability: Credinberg credentials can be uploaded and verified on standard Open Badges validators, digital credential wallets, and enterprise verification platforms worldwide.

Access Governance & Authentication Controls

We enforce comprehensive authentication safeguards and granular authorization controls across all account tiers:

  • DNS-Based Domain Ownership Verification: Issuing organizations must prove administrative authority over their official web domain via cryptographic DNS TXT record validation before publishing verified credentials.
  • Verification via One-Time Passwords (OTP): Enforces secure email verification codes for account onboarding, email linking, and sensitive password updates.
  • Brute-Force Protection: Automated rate limiting and lockout safeguards protect accounts against credential stuffing and brute-force attacks.
  • Role-Based Access Control (RBAC): Granular permissions within workspaces: Owner, Admin, Issuer, and Viewer roles ensure team members access only what their function requires.
  • Session Management: Sessions use short-lived secure tokens. User sign-out immediately revokes the active session token.

Application & Network Defense

Credinberg deploys defense-in-depth security controls to guard against volumetric attacks and common web vulnerabilities:

  • DDoS & Web Application Protection: Edge proxy layers filter and mitigate distributed denial-of-service (DDoS) attacks before traffic reaches backend servers.
  • Abuse & Bot Prevention: Automated rate-limiting and threat detection block abusive scrapers and unauthorized automated scripts.
  • Security Headers: Core dashboard, passport, and authentication routes enforce Content Security Policy (CSP) and frame-ancestor protections to prevent clickjacking and unauthorized embeds.
  • Parameterized Queries: Database queries are executed strictly through parameterized statements, preventing SQL injection vulnerabilities.

Business Continuity & Backups

To ensure uninterrupted service and data durability, Credinberg maintains multi-tier recovery safeguards:

  • Automated Backups: Continuous write-ahead backups and snapshot copies are maintained across geographically separated locations to prevent data loss.
  • Disaster Recovery Testing: Infrastructure as code allows rapid environment recovery and point-in-time restoration in emergency scenarios.

Authorized Subprocessors & Vendor Due Diligence

Credinberg partners strictly with enterprise infrastructure and cloud providers that hold certified security standards (SOC 2 Type II, ISO/IEC 27001) and maintain strict Data Processing Addendums (DPAs) with Standard Contractual Clauses (SCCs):

SubprocessorService ScopeData LocationSecurity Certifications
Supabase, Inc. (AWS)Primary database hosting, row-level tenant isolation & auth vaultsUnited StatesSOC 2 Type II, ISO 27001
Cloudflare, Inc.Global Edge WAF, encrypted R2 object storage & DDoS protectionGlobal Edge NetworkSOC 2 Type II, PCI-DSS
Vercel, Inc.Edge application compute runtime & cryptographic SSR renderingGlobal EdgeSOC 2 Type II, ISO 27001
Resend, Inc.Transactional security alerts, OTP verifications & claim emailsUnited StatesSOC 2 Type II
PostHog, Inc.Product telemetry & retention metrics (session recording disabled)United States / EUSOC 2 Type II, EU-US DPF
Microsoft CorporationMicrosoft Clarity UX telemetry with automated PII maskingUnited StatesISO 27001, SOC 2 Type II
Google LLCGoogle Tag Manager telemetry containerizationUnited StatesISO 27001, SOC 2 Type II
Stripe, Inc.Subscription billing settlement & encrypted merchant processingUnited StatesPCI-DSS Level 1

Responsible Vulnerability Disclosure

We value the vital contribution of independent security researchers. If you identify a potential security vulnerability within Credinberg systems:

  • Submit reports directly to security@credinberg.com with reproducible steps.
  • Provide reasonable time for our engineering team to investigate and remediate before public disclosure.
  • Do not degrade platform availability, execute volumetric denial-of-service, or compromise customer privacy.
Next Document

Terms of Service

Review customer intellectual property rights, acceptable credential issuance policies, and enterprise service guarantees.

Read Terms of Service

Credinberg Global Governance & Compliance Office

Authoritative legal and privacy policy repository. Inquiries may be directed to legal@credinberg.com.