Trust

Security

This page is maintained by MegaBridge Digital to answer common security questions about MegaBridge Marketplace Studio. It describes the controls in place today and is not a certification or independent audit.

Authentication and access

Accounts sign in with email and password or Google. Sessions are managed by our authentication provider, and every workspace route requires an authenticated session.

Data isolation

Projects, jobs, credits and assets are scoped per account with row-level access rules enforced in the database, so one workspace cannot read another's records.

File storage

Uploads and generated assets are held in private buckets. Files are served through short-lived signed URLs rather than public links.

Provider keys

AI provider credentials, including the image processing key, are stored server-side and used only inside authenticated server functions. The browser never receives or calls a provider directly.

Payments

Card details are handled by Stripe and mobile money by Safaricom M-Pesa. We do not store card numbers. Payment callbacks are signature-verified before any credit is granted.

Transport

All traffic to the studio and its APIs is served over HTTPS.

Shared responsibility

We secure the platform, its infrastructure and provider integrations. You are responsible for protecting your credentials, managing who has access to your workspace, and confirming you hold the rights to the imagery you upload.

Reporting a vulnerability

Send findings to security@megabridgedigital.com. Please include reproduction steps and give us reasonable time to remediate before public disclosure.