SECURITY & TRUST

Clear boundaries. Accountable design.

Understand how Etchv handles access and image identity, and what to evaluate before a production integration.

Authentication and permissions

The API separates Clerk session authentication for account administration from scoped API keys for image operations. Application organizations and membership roles control access. Keep machine credentials on your server, never in public browser code.

API-key lifecycle

The current API issues keys with an expiry of 1–365 days, defaulting to 90. It stores a SHA-256 digest rather than the original key. Keys can be revoked, and image requests check key status and current membership.

Image and reference handling

Images are processed for embedding or detection. The account database does not store image files or supplied watermark payloads. This does not imply a contractual zero-retention policy across all infrastructure; contact us to discuss your deployment and processing requirements.

Privacy-aware attribution

Keep the recipient mapping in your own records. Prefer opaque IDs and minimize personal information in watermark payloads. A digest is not encryption and should not be treated as a way to make sensitive input safe to disclose.

Deployment and assurance

Ask us about the applicable hosting region, retention, incident handling and contractual terms before sharing sensitive content. This site does not claim SOC 2 certification, a production uptime SLA or guaranteed resistance to every transformation.

Report a concern

Send security questions or a vulnerability report to hello@etchv.com. Share a concise description and reproduction steps, and avoid including live credentials or sensitive customer content.

MAKE EVERY COPY ACCOUNTABLE

Your content has a story.
Keep it connected.

Let’s find the right watermarking workflow for your platform.

Talk to the team