Docs / Support
Security
Key handling, current safeguards, and security questions.
Current implementation
The beta stores API keys as SHA-256 hashes, separates publishable and secret key permissions, checks revoked keys and disabled accounts, and applies per-key burst protection. Key lookups can be cached for up to a minute.
Account sign-in uses a one-time link sent only to an email already enabled for beta access. The link expires after 15 minutes and can be used once. Dashboard sessions expire after 14 days; the browser keeps the session token in tab-scoped session storage, and sign-out revokes it server-side. New API keys are shown only when created; the database stores their hashes.
Publishable domain restrictions allow requests without a referrer; they are not an access-control boundary for confidential data. Domain-setting changes and key revocation can take up to a minute to affect cached key checks. Logos are public brand assets. Keep secret keys on your server and redact request credentials before sharing logs.
Report a concern
Contact brands@brandmarks.dev with a concise description and affected endpoint. Start without sensitive payloads or credentials and ask for a suitable way to share reproduction details. If your key is exposed, revoke it in the account portal and create a replacement.
A public security policy, dedicated disclosure channel, retention schedule, DPA, and compliance attestations are not provided by these docs. Do not infer certification or a contractual security commitment. Ask about your requirements before sending sensitive information or adopting the service for a regulated workflow.
Need a hand? Get help · Technical content reviewed October 2, 2026