Security
Last updated: February 22, 2026
Security is built into every layer of the Centyr platform, from the infrastructure we run on to the way your images are stored and deleted.
Infrastructure
Centyr runs on AWS in the eu-west-3 (Paris) region. All user data stays within the EU.
- API server on AWS EC2 behind Nginx reverse proxy
- Image processing on AWS ECS Fargate (isolated containers per workload)
- Image storage on Amazon S3 with private ACLs and server-side encryption (AES-256)
- Database on Amazon DynamoDB with encryption at rest
- All services run inside an AWS VPC with strict security groups
Encryption
- In transit: TLS 1.2/1.3 enforced on all connections. HTTP is permanently redirected to HTTPS. Cipher suites restricted to ECDHE with AES-GCM and ChaCha20-Poly1305.
- At rest: S3 objects encrypted with AES-256 (SSE-S3). DynamoDB tables encrypted at rest. Backups encrypted.
- Presigned URLs: Temporary access URLs for images expire after 1 hour. No image is ever publicly accessible.
Network Security
- Cloudflare: All traffic passes through Cloudflare for DDoS protection, Web Application Firewall (WAF), and rate limiting before reaching our servers
- Security groups: EC2 and ECS instances only accept traffic from Cloudflare IP ranges and internal services
- No public S3 access: S3 buckets have public access fully blocked. Files are accessible only via authenticated presigned URLs
- CORS: Cross-Origin Resource Sharing is restricted to centyr.tech only
Authentication & Access Control
- User authentication managed by AWS Cognito, we never store passwords directly
- JWTs signed with RS256; public keys verified from Cognito's JWKS endpoint (refreshed hourly)
- OAuth 2.0 supported (Google, Apple) for passwordless sign-in
- All API endpoints require a valid Bearer token; no sensitive endpoint is publicly accessible
- AWS IAM roles follow least-privilege principle, each service has only the permissions it needs
- Internal AWS credentials use IAM instance roles; no long-lived access keys in application code
Data Isolation
Your data is fully isolated from other users:
- Every S3 object is stored under a path scoped to your user ID
- All API endpoints validate that the requesting user owns the resource before serving it
- Job IDs are UUIDs; sequential enumeration is not possible
- Processing containers (ECS Fargate) are ephemeral and isolated, they do not share memory or storage across jobs
Data Retention & Deletion
- Uploaded images are automatically deleted after 30 days via S3 lifecycle policy
- Processed output images are automatically deleted after 30 days
- Account data is deleted within 30 days of an account deletion request
- Billing records are retained for 7 years as required by Italian tax law
- You can request immediate deletion of your data by emailing [email protected]
Application Security
- HTTP security headers on all responses:
X-Frame-Options: DENY,X-Content-Type-Options: nosniff,HSTS,Content-Security-Policy - File uploads validated by MIME type (magic bytes), not just file extension
- Maximum upload size enforced at both the API and Nginx levels
- All user-supplied path parameters (job IDs) validated as UUIDs to prevent injection
- Internal error details never exposed in API responses
- Payment processing handled exclusively by Stripe, card data never touches our servers
Payments Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment provider. Centyr never stores, transmits, or has access to your card number, CVV, or full billing details. Stripe's security practices are documented at stripe.com/docs/security.
Vulnerability Disclosure
We take security vulnerabilities seriously. If you discover a security issue in the Centyr platform, please report it responsibly:
- Email: [email protected]
- Please include a description of the vulnerability and steps to reproduce it
- We will acknowledge your report within 48 hours and aim to resolve critical issues within 7 days
- We request that you do not publicly disclose the vulnerability until we have had the opportunity to address it
Incident Response
In the event of a security incident affecting your personal data, we will:
- Notify affected users within 72 hours if required under GDPR Art. 34
- Report the incident to the Italian DPA (Garante) within 72 hours as required by GDPR Art. 33
- Provide details on the nature of the breach, data affected, and steps taken to mitigate it