Security by design.
Built on cryptographic proof.

Keepsake uses server-side authorization, immutable audit trails, and cryptographic integrity checks to protect creative handovers. No security shortcuts.

Security Principles

How Keepsake protects your work and proves what was approved.

Token-Scoped Client Access

Clients access vaults via 256-bit cryptographic tokens, not usernames. Tokens are non-enumerable and cannot be guessed. Optional passcodes add an additional security layer without requiring client accounts.

Immutable File-Byte Hashes

SHA-256 signatures bind directly to the binary bytes of uploaded files. Database triggers lock approved versions permanently. Even a single byte change invalidates the hash, making tampering immediately detectable.

Server-Side Authorization

Original files remain locked on secure storage. Presigned download URLs are only issued after the database records a completed sign-off. Clients cannot circumvent this gate—access control is enforced server-side.

Immutable Audit Trail

Every vault action—upload, review, revision request, approval, sign-off, download—is timestamped and appended to an append-only log. Audit records cannot be altered or deleted, creating a permanent record of the handover.

Watermarked Previews

Clients review watermarked previews, not original files. This separates viewing rights from download access. Originals remain on secure storage until approval is recorded.

Expiry & Revocation

Vaults can be configured with optional expiry dates. After expiry, the vault link becomes inaccessible. Creators can also manually revoke vault access at any time.

SHA-256 File Integrity

When you upload a file to Keepsake, we calculate its SHA-256 hash—a unique digital fingerprint of the exact binary bytes. This hash becomes part of the approval record.

When the client approves, their signature binds directly to this hash. If even a single byte changes, the hash changes completely. This makes tampering immediately detectable.

Years later, you can verify that the certificate file matches the original by comparing hashes. There's no ambiguity—cryptography proves what was delivered.

Original File Hash
9f830a174c219ba48d1e3f89012a4b8c9e120f384a51e60b78c9d01234567890
Approval Signature (Binds to Hash)
Client: Sarah Chen
Approved: March 14, 2025
Hash: 9f830a174c219ba48...
Any Change = Different Hash
5a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f (✗ No match)

Infrastructure & Services

Keepsake is built on industry-standard cloud services with strong security records.

Supabase (PostgreSQL)

Primary data store. Database triggers enforce immutability of approved records. Row-level security policies ensure users can only access their own vaults. Backups are replicated for availability.

Cloudflare R2

Secure file storage. R2 handles presigned URLs for authenticated downloads. Files are encrypted in transit and at rest. Access is restricted to authenticated backend requests only.

Vercel & Next.js

Application hosting. Server-side authorization is enforced in route handlers and server actions. No client-side logic can bypass access controls.

Stripe

Payment processing. Keepsake handles billing securely via Stripe, never storing payment card data directly. Subscription status is verified server-side.

Resend

Transactional email. Approval notifications and certificate delivery emails are sent through Resend's secure infrastructure. Email contents do not include sensitive file data.

keepsake.regentic.co.uk/vault/sk_7a3c4f2b9d1e8k5p...
256-bit cryptographic token
Optional Passcode
••••••••

Client Vault Access

Clients access your vaults via secure links containing 256-bit cryptographic tokens. No usernames. No account creation. No password resets.

Tokens are cryptographically random and cannot be guessed
Tokens are non-enumerable—knowing one token reveals nothing about others
Optional passcodes add a second factor without requiring accounts
Vaults can be configured with automatic expiry dates
Creators can revoke access at any time

What We Don't Do

No "military-grade" claims

We use industry-standard encryption (TLS 1.3, SHA-256). No marketing nonsense.

No unverified certifications

We don't claim SOC 2, ISO 27001, or GDPR compliance we haven't actually obtained.

No backdoors

Server-side authorization is enforced in code. No admin shortcuts. Audit trails are immutable.

No analytics tracking

Keepsake does not run Google Analytics, segment tracking, or third-party ad pixels.

No third-party cookies

We use only essential cookies for authentication and session management.

No client data monetization

Your vault data is never sold, shared, or used for training models.

Privacy & Data

Keepsake processes vault information (creative files, client names, approval records) to deliver the handover service. This data is stored securely and not shared with third parties.

For full details on data processing, see our Privacy Policy.

Questions about security? Contact us at hello@regentic.co.uk