Security Architecture
At APIPLAY, security is not an afterthought — it's the core foundational directive of the platform. We built this gateway to keep your production credentials out of the hands of non-technical staff while still empowering them to perform their jobs.
1. Zero Client-Side Secrets
The defining security feature of APIPLAY is that API credentials (such as Stripe API keys, OAuth Bearer tokens, or database passwords) never reach the user's browser.
When an engineer configures a portal, the API keys are encrypted immediately and stored in the backend vault. When a staff member runs a query, the frontend only sends the unauthenticated form data to our gateway. The backend retrieves the vault credentials, decrypts them in memory, attaches them to the outgoing HTTP request, and proxies the call to your API.
2. AES-256 Vault Encryption
All vault secrets are encrypted at rest using AES-256-CBC. The encryption keys are managed via environment variables and are never stored in the database alongside the ciphertexts.
3. Stateless JWT Authentication
User authentication relies on short-lived JSON Web Tokens (JWTs). We do not maintain server-side session state, significantly reducing the attack surface. Sensitive routes (like creating portals or modifying environments) enforce strict role-based access control (RBAC), verifying that the user is an Administrator or Developer on every single request.
4. Immutable Audit Logging
Every API execution is permanently logged to an immutable MySQL table. The audit log records:
- The authenticated user's email address and ID
- The portal and environment executed
- The timestamp and execution duration
- The sanitized input payload
- The HTTP response status code
Crucially, we do not log your API keys, nor do we permanently store third-party API response bodies.
5. Strict Input Sanitization
All user inputs from the visual form builder are strongly typed and sanitized before being injected into the downstream API request. This prevents injection attacks and ensures that the payload matches the expected schema defined by the developers.
If you have specific compliance requirements or questions about our architecture for SOC 2 or ISO 27001 readiness, please contact us at: security@markuting.com.