BakeFrame

Trust · Last updated 1 July 2026

Security

BakeFrame is built around the principle that you should never have to trust us with your content or your infrastructure costs. Our BYO* architecture means your IP and credentials stay under your control by design.

AES-256-GCM Encrypted API Keys

Every API key you add to BakeFrame is encrypted at rest using AES-256-GCM with a server-side encryption key stored separately from the database. Keys are decrypted only in memory at request time and are never logged, indexed, or exposed via any API response.

Your Storage, Your Media

With BYOS enabled, generated videos, images, and audio are written directly from the AI provider to your storage bucket (S3, Azure Blob, R2, GCS). Media never transits through our servers, which means your unreleased IP is never stored by us.

Transport Security

All connections to bakeframe.art are encrypted via TLS 1.2+. HSTS is enforced. We use secure, HttpOnly cookies for session tokens, and all sensitive endpoints require authentication.

Error Monitoring & Incident Response

We use Sentry for real-time error detection, scoped to anonymized context. Our on-call process targets a 4-hour acknowledgement window for critical security incidents. We follow responsible disclosure and will notify affected users within 72 hours of a confirmed breach.

Responsible Disclosure

If you discover a security vulnerability in BakeFrame, please report it privately before public disclosure. We commit to acknowledging your report within 2 business days and working toward a fix within 30 days.

hello@bakeframe.art →