Security by design.
Built on cryptographic proof.
Keepsake uses server-side authorization, immutable audit trails, and cryptographic integrity checks to protect creative handovers. No security shortcuts.
Security Principles
How Keepsake protects your work and proves what was approved.
Token-Scoped Client Access
Clients access vaults via 256-bit cryptographic tokens, not usernames. Tokens are non-enumerable and cannot be guessed. Optional passcodes add an additional security layer without requiring client accounts.
Immutable File-Byte Hashes
SHA-256 signatures bind directly to the binary bytes of uploaded files. Database triggers lock approved versions permanently. Even a single byte change invalidates the hash, making tampering immediately detectable.
Server-Side Authorization
Original files remain locked on secure storage. Presigned download URLs are only issued after the database records a completed sign-off. Clients cannot circumvent this gate—access control is enforced server-side.
Immutable Audit Trail
Every vault action—upload, review, revision request, approval, sign-off, download—is timestamped and appended to an append-only log. Audit records cannot be altered or deleted, creating a permanent record of the handover.
Watermarked Previews
Clients review watermarked previews, not original files. This separates viewing rights from download access. Originals remain on secure storage until approval is recorded.
Expiry & Revocation
Vaults can be configured with optional expiry dates. After expiry, the vault link becomes inaccessible. Creators can also manually revoke vault access at any time.
SHA-256 File Integrity
When you upload a file to Keepsake, we calculate its SHA-256 hash—a unique digital fingerprint of the exact binary bytes. This hash becomes part of the approval record.
When the client approves, their signature binds directly to this hash. If even a single byte changes, the hash changes completely. This makes tampering immediately detectable.
Years later, you can verify that the certificate file matches the original by comparing hashes. There's no ambiguity—cryptography proves what was delivered.
9f830a174c219ba48d1e3f89012a4b8c9e120f384a51e60b78c9d01234567890Client: Sarah Chen
Approved: March 14, 2025
Hash: 9f830a174c219ba48...5a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f (✗ No match)Infrastructure & Services
Keepsake is built on industry-standard cloud services with strong security records.
Supabase (PostgreSQL)
Primary data store. Database triggers enforce immutability of approved records. Row-level security policies ensure users can only access their own vaults. Backups are replicated for availability.
Cloudflare R2
Secure file storage. R2 handles presigned URLs for authenticated downloads. Files are encrypted in transit and at rest. Access is restricted to authenticated backend requests only.
Vercel & Next.js
Application hosting. Server-side authorization is enforced in route handlers and server actions. No client-side logic can bypass access controls.
Stripe
Payment processing. Keepsake handles billing securely via Stripe, never storing payment card data directly. Subscription status is verified server-side.
Resend
Transactional email. Approval notifications and certificate delivery emails are sent through Resend's secure infrastructure. Email contents do not include sensitive file data.
••••••••Client Vault Access
Clients access your vaults via secure links containing 256-bit cryptographic tokens. No usernames. No account creation. No password resets.
What We Don't Do
No "military-grade" claims
We use industry-standard encryption (TLS 1.3, SHA-256). No marketing nonsense.
No unverified certifications
We don't claim SOC 2, ISO 27001, or GDPR compliance we haven't actually obtained.
No backdoors
Server-side authorization is enforced in code. No admin shortcuts. Audit trails are immutable.
No analytics tracking
Keepsake does not run Google Analytics, segment tracking, or third-party ad pixels.
No third-party cookies
We use only essential cookies for authentication and session management.
No client data monetization
Your vault data is never sold, shared, or used for training models.
Privacy & Data
Keepsake processes vault information (creative files, client names, approval records) to deliver the handover service. This data is stored securely and not shared with third parties.
For full details on data processing, see our Privacy Policy.
Questions about security? Contact us at hello@regentic.co.uk