Security
This page is maintained by MegaBridge Digital to answer common security questions about MegaBridge Marketplace Studio. It describes the controls in place today and is not a certification or independent audit.
Authentication and access
Accounts sign in with email and password or Google. Sessions are managed by our authentication provider, and every workspace route requires an authenticated session.
Data isolation
Projects, jobs, credits and assets are scoped per account with row-level access rules enforced in the database, so one workspace cannot read another's records.
File storage
Uploads and generated assets are held in private buckets. Files are served through short-lived signed URLs rather than public links.
Provider keys
AI provider credentials, including the image processing key, are stored server-side and used only inside authenticated server functions. The browser never receives or calls a provider directly.
Payments
Card details are handled by Stripe and mobile money by Safaricom M-Pesa. We do not store card numbers. Payment callbacks are signature-verified before any credit is granted.
Transport
All traffic to the studio and its APIs is served over HTTPS.
Shared responsibility
We secure the platform, its infrastructure and provider integrations. You are responsible for protecting your credentials, managing who has access to your workspace, and confirming you hold the rights to the imagery you upload.
Reporting a vulnerability
Send findings to security@megabridgedigital.com. Please include reproduction steps and give us reasonable time to remediate before public disclosure.