Documentation

Log in

Security

Last updated: 2026-03-12

momentake applies layered technical and organizational measures to protect users’ data and media. This page describes the controls currently used in the product and infrastructure.

Transport and perimeter protection

Traffic to the platform is delivered over HTTPS. API responses include baseline security headers via Helmet, and CORS is restricted to trusted origins (including validated custom-domain flows).

Authentication and access control

Protected API endpoints require bearer JWT authentication. Tokens are verified server-side, invalid/expired tokens are rejected, and access from soft-deleted accounts is blocked. Admin endpoints add role checks on top of authentication.

Protected media delivery

Private downloads use time-limited HMAC-signed URLs. HLS streaming is token-gated and can use secure cookies with HttpOnly, Secure, SameSite=None, and path scoping. Cloudflare Worker validates tokens/signatures before serving media.

Gallery-level protection

Public gallery links can be password-protected. Passwords are stored as bcrypt hashes and verified on access, helping prevent plaintext credential exposure.

Abuse prevention and input validation

API endpoints use route-level rate limiting to reduce abuse and brute-force attempts. Request data is validated with Zod schemas for params/query/body, and invalid input is rejected with structured errors.

Payment and webhook integrity

Monobank webhook events are verified using cryptographic signatures against the raw request body before processing, reducing the risk of forged callback events.

Operations, monitoring, and incident response

Security checks in CI include dependency, code, secret, and configuration scanning, with scheduled baseline security scans. Incident-response procedures define triage, containment, evidence handling, escalation, and GDPR notification assessment targets.

Data rights, deletion, and transparency

Users can submit DSAR requests (data export and account erasure) and track statuses in-product. Account-deletion workflows remove stored assets and anonymize related personal fields. Subprocessors and data-hosting transparency are published, including EU-region B2 storage details.