Trust center

Security at AP Studio

AP Studio uses layered controls to protect account information, OAuth credentials, generated media, and application data.

Last updated: July 22, 2026 Security contact: sarievibragim8@gmail.com
TLS

Encrypted transmission

Public application traffic is protected with HTTPS/TLS.

AES

Encrypted OAuth storage

OAuth credentials and tokens are encrypted at rest using AES-256-GCM.

ACL

Restricted access

User separation, permissions, and server-side controls limit access to sensitive data.

Operational security controls

  • OAuth secrets and tokens are not displayed in full in ordinary user-facing interfaces.
  • Sensitive encryption material is stored separately with restricted filesystem permissions.
  • Application accounts and administrative functions are protected by authentication and authorization controls.
  • Service events and failures are logged to support diagnostics and incident investigation.
  • Backups are created for operational recovery and must be handled as sensitive data.
  • Platform access may be revoked by disconnecting an account or revoking authorization at the provider.

User security responsibilities

  • Use a strong, unique AP Studio password and enable available account-protection features.
  • Do not share OAuth client secrets, API keys, session cookies, or access tokens.
  • Review connected accounts and remove connections that are no longer required.
  • Report unexpected publications, login events, or account changes promptly.

Report a security concern

Send a clear description, affected URL, approximate time, and supporting technical details to sarievibragim8@gmail.com. Do not include passwords, full access tokens, or unrelated personal data.

No system can guarantee absolute security, but reported issues are reviewed and addressed according to their impact and available evidence.