Private by default
Provider credentials and license signing keys belong on the server or in the appropriate secret store.
A commercially deployed platform needs clear boundaries, careful handling of secrets and verifiable operating procedures.
The foundation includes server-side authentication, protected administrative workflows, signed payment webhook handling and activity logging. Castmere adds signed license verification, private deployment configuration and sanitized diagnostics.
Provider credentials and license signing keys belong on the server or in the appropriate secret store.
Customer data, accounts, credentials and infrastructure require explicit isolation between deployments.
Backups, recovery, media authorization, payment reconciliation and service health must be verified before a production launch.
Password sign-in, TOTP MFA and recovery flows are implemented. Sensitive customer API and webhook administration requires verified MFA and scoped permissions. No SOC 2, ISO 27001 or other certification is claimed; security, dependency and operational acceptance remain deployment requirements.
Discuss your requirements