Architectural Security by Default
We believe personal memories are among the most sensitive data humans possess. Privacy in Echoes is enforced mathematically and architecturally.
The Echoes Security Contract
The application follows a constitution-first security model where the server is the sole authoritative decision-maker. Client-side checks are never relied upon for authorization.
Authoritative Clerk JWT Verification
All requests are cryptographically verified server-side. Application users are synchronized idempotently into PostgreSQL. No unauthenticated requests reach private data.
Strict Tenant Scoping
Every SQL query enforces `owner_id = user.id`. Cross-user access attempts return HTTP 404 (Not Found) rather than 403 to prevent resource enumeration attacks.
Private Cloud Object Storage
Media buckets are private. Files are stored at structured paths `users/{userId}/captures/...` and accessed strictly via short-lived signed URLs generated only after server-side ownership checks.
Multi-Tier Sliding Window Rate Limiting
Independent rate limiters protect upload endpoints (10/min), AI queries (20/min), authentication flows (5/min), and admin mutations (30/min).
Atomic Usage Reservations
Token consumption and model execution are gated by sliding-window policies with atomic reservations to eliminate concurrency race conditions.
Immutable Administrative Audit Trail
Sensitive operations (account suspensions, role elevation, policy overrides) are permanently recorded in append-only audit tables with IP and timestamp.
What Echoes Will Never Do
- ✕We will never train public AI models on your personal photographs, voice recordings, or transcripts.
- ✕We will never expose raw storage keys or unauthenticated public URLs to user media.
- ✕We will never allow an algorithm to unilaterally declare unreviewed AI proposals as permanent memories.
- ✕We will never sell or monetize personal archives or memory graph metadata.
Start preserving with peace of mind
Built on proven zero-trust security and modern tenant isolation.