SnapKey homepage
SECURITY

Security & TOMs

1. Security objectives

SnapKey applies risk-based measures intended to protect confidentiality, integrity, availability and resilience. Measures are reviewed when the service, threat landscape, providers or legal requirements change.

2. Access and authorization

  • private-by-default Guest galleries and project-scoped access checks;
  • separate random Guest, Master and sharing credentials;
  • hashed passwords and time-limited Master, sharing and administration sessions;
  • configurable upload, view and deletion permissions; and
  • deactivation and archival controls for project and Guest access.

3. Encryption and secrets

  • HTTPS/TLS for data in transit;
  • encrypted OAuth access and refresh tokens at rest;
  • provider-side encryption for managed photos stored in Cloudflare R2 with EU jurisdiction;
  • secrets kept outside public source code and browser responses; and
  • no storage of cloud-account passwords by SnapKey.

4. Data minimization and separation

  • project-scoped identifiers and storage paths;
  • pseudonymous Guest recovery identifiers instead of required Guest accounts;
  • only operational photo metadata stored in the application database;
  • customer-selected Google Drive access limited to the permissions requested during OAuth; and
  • Cloudflare R2 managed storage separated by project and quota.

5. Secure operation

  • server-side authorization and input validation for protected actions;
  • file-size, media-type and configurable quota controls;
  • activity records for security-relevant actions without passwords, QR tokens or OAuth secrets;
  • automatic removal of application activity logs after 30 days; and
  • restricted administrative functions and warning steps for destructive actions.

6. Availability and recovery

SnapKey uses provider infrastructure designed for distributed delivery and object durability. Capacity warnings and storage checks reduce failed uploads. Customers remain responsible for exports or additional backups appropriate to the importance of their photos. Recovery procedures, alerting and restore tests are documented and exercised regularly.

7. Incident response

Suspected incidents are assessed, contained, documented and remediated. Where Customer personal data is affected, SnapKey will provide available information about the nature of the incident, affected data and people, likely consequences and mitigation without undue delay. The Customer remains responsible for its notification duties as controller.

8. Personnel and providers

Access is limited to persons who need it to operate or support the service and who are subject to confidentiality duties. Providers are selected with regard to security, contractual safeguards and data location. Current information is available on the Subprocessors page.

9. Review and evidence

SnapKey maintains a current asset and processing inventory, access review, deletion procedure, vulnerability and dependency process, incident register, provider review and documented tests of recovery measures. Material findings must be tracked to resolution.

← Back to SnapKey