Security
Keep content inside a clear trust boundary.
Product requests, content transfer, retention, and deletion stay within explicit, verifiable boundaries.
Request boundary
The browser never enters the service interior.
A project ID selects a project for authorization; it does not grant access. Product requests always pass through the server boundary.
01
Browser
Initiates product actions and receives only the page model and asset-scoped capability it needs.
02
Controlled boundary
The backend for frontend manages sessions, project selection, request allowlists, and sensitive-field removal.
03
Service state
The VedoBox public API remains the owner of VedoBox media, tasks, authorization, and execution state.
Content lifecycle
Service state governs transfer through deletion.
The interface reflects persisted policy and state instead of treating one accepted request as a final outcome.
01
Scoped transfer
Uploads and downloads use only short-lived, asset-scoped capabilities returned by the BFF.
BoundarySigned URLs and object keys stay out of logs, analytics, and browser persistence; expired capabilities are requested again.02
Content retention
Content is retained for 30 days by default, with a configurable maximum of 90 days.
BoundaryRetention comes from service state; the interface does not extend, replace, or invent expiration dates.03
Deletion state
Deletion revokes access first, then removes media and related content asynchronously.
BoundaryAn accepted deletion request is not presented as physical deletion before asynchronous cleanup completes.
Privacy principles
Sensitive content is not diagnostic material.
These statements describe the current architecture and product rules, not an unfinished formal certification.
Do not log content
Media, subtitles, signed URLs, object keys, tokens, and provider responses stay out of logs and analytics.
Keep service secrets out of the browser
Service API keys and configured identity credentials remain inside the controlled server boundary.
Do not overstate assurance
Unverified certification and compliance status is not presented as a product promise.
Continue with the integration boundary.
See the current status of the candidate public API, unavailable Webhook controls, and private SDK candidates.
