Security
Secure Quat credentials, buckets, CORS policies, and storage integrations.
Access Key Handling
Treat Quat access keys like production credentials:
- Store them in environment variables or a secret manager.
- Do not commit them to Git.
- Do not expose secret keys in frontend code.
- Use separate credentials per environment when supported.
Secret Key Storage
The console reveals secret keys only after protected confirmation. If a secret key is lost, regenerate the key pair and update every application using the old credentials.
HTTPS And TLS
Use HTTPS for:
- The Quat customer console.
- The Quat backend API.
- The S3-compatible storage endpoint.
Local development may use HTTP, but production deployments should terminate TLS with certificates trusted by your client applications.
Bucket Permissions
The app models bucket and object privacy concepts in the UI, but the exact storage permission model is enforced by the backend and storage layer. Keep buckets private unless there is a specific reason to expose public reads.
Least Privilege
Where your deployment supports multiple accounts or scoped credentials:
- Use separate credentials for each application.
- Limit credentials to required buckets.
- Rotate keys on team changes or suspected exposure.
Credential Rotation
To rotate credentials:
- Open Settings then API Keys.
- Regenerate keys.
- Update application secrets.
- Restart applications or reload secret configuration.
- Confirm uploads and downloads work.
CORS Security
Avoid overly broad browser access:
- Prefer explicit origins over
*. - Allow only required methods.
- Allow only required headers where possible.
- Keep
MaxAgeSecondsreasonable.
Example restricted CORS rule:
{
"AllowedOrigins": ["https://app.example.com"],
"AllowedMethods": ["GET", "PUT"],
"AllowedHeaders": ["Authorization", "Content-Type"],
"ExposeHeaders": ["ETag"],
"MaxAgeSeconds": 3600
}
Logging And Auditing
The customer app includes usage views, but no dedicated audit log UI. For compliance-sensitive deployments, keep backend API logs, auth logs, storage access logs, and payment event logs.
Backup Protection
Protect backups with the same care as primary object storage:
- Encrypt backup media.
- Restrict restore permissions.
- Test restoration.
- Keep backup credentials separate from application credentials.