Layered protection with clear responsibilities

Security is ongoing work shared by the application, providers, and users. This page describes confirmed controls at a general level; it does not publish secrets or exploitable configuration, and it does not claim certifications Vistral Studio has not substantiated.

Authentication and access control

Spark uses Supabase for authentication. Sessions and access checks separate public areas from projects and features associated with an account.

Authentication does not remove basic precautions: use unique credentials, protect the associated email account, and sign out on devices you do not control.

Credentials stay out of public content

Application secrets, tokens, and provider credentials should not appear on pages, in analytics, or in support messages. Integrations such as YouTube rely on their own authorization and permissions.

Spark will not ask you to publish tokens to receive help. If a credential is exposed, revoke it with the relevant provider before sharing a sanitized report.

Payments through a specialized provider

Stripe processes payments and subscriptions. Review the purchase summary at checkout; full card details should never be sent to Vistral Studio by email or contact form.

Using Stripe does not amount to claiming a security certification for Spark. Each service has distinct responsibilities in the flow.

Projects and files require authorized access

Projects, uploaded images, and results belong to the account context and are not public content by default. Upload only files you are allowed to process, and avoid unnecessary secrets, documents, or personal data in references.

Public links and exports are controlled by the person who chooses to share them. Review the content before distributing a file outside the platform.

Reporting a possible vulnerability

Use the contact channel and describe the impact, a safe reproduction path, and the affected environment. Do not access third-party data, disrupt the service, or include tokens, passwords, or personal data in the initial report.

Receiving a report does not imply a bounty program or a guaranteed response time. It enables triage and responsible coordination.

Frequently asked questions

Is Spark SOC 2 or ISO 27001 certified?

This page does not claim either certification for Spark. Providers used by the application may operate their own programs, which must not be automatically attributed to Vistral Studio.

Can I send a password or token to support?

No. Revoke any exposed credential and send only sanitized information that explains the issue without granting access to your account.

Do my images automatically become public examples?

No. Account projects and uploads are not public content by default. Publishing or sharing requires a separate action and context.

Found a security issue?

Send a responsible report with the minimum necessary information, and never include passwords, tokens, or third-party content.

Layered protection with clear responsibilities | Vistral Studio Spark