# Security

A short summary of how Mestra protects your data.

This page is a short summary. The full detail is on [Security and privacy](https://withmestra.com/security/) and the [Trust centre](https://withmestra.com/trust/). If this page and those differ, they win.

## The short version

- **Your artwork isn't kept.** Mestra reads the structure of your master to lay out a format. It doesn't keep the artwork or copy it reads. Settings you enter, such as campaign copy and logos, are kept until you delete them.
- **The file library is optional.** It is off by default. When an owner turns it on, exported files are kept for 30, 90 or 365 days. Files are encrypted with a key unique to your organisation, and deleted when they expire. See [The file library](https://withmestra.com/docs/concepts/library/).
- **Hosted in Sydney.** Mestra's service and database run in Sydney. Traffic is protected by Cloudflare. Some data is processed or held overseas. The [Trust centre](https://withmestra.com/trust/) lists where.
- **Access is by role.** People join as owners, editors or viewers. Sign-in is by emailed link, Google or Microsoft (work and school accounts). InDesign and Figma connect through a browser approval, so nobody pastes passwords or tokens. Canva links by team: an owner links the team, then each person signs in. See [Sign in](https://withmestra.com/docs/account/sign-in/).
- **There is an audit log.** Sign-ins, membership and configuration changes and staff actions are recorded and kept for one year.

## Staff access

Mestra staff reach the admin console only through Cloudflare Access and their own sign-in. To help with a support request, a staff member can open your organisation as an owner would, for up to an hour, after recording a reason. They can start runs, edit brands, campaigns and formats, and save library files while they act. They can't change roles, invite or remove people, remove an owner, unlink an owner's sign-in, create app sign-ins or download links, or touch billing. Each session, its reason and every change made are recorded in your audit log. Owners can see what support did, and why, on **Organisation** > **Activity**.

## Report a security issue

Email <security@withmestra.com>. We'll reply within two business days. The [Trust centre](https://withmestra.com/trust/) has our disclosure policy.

## Certifications

Mestra has no SOC 2 or ISO 27001 certification yet, and no independent audit or penetration test. A security pack is available on request from the [Trust centre](https://withmestra.com/trust/).

## Related

- [Security and privacy](https://withmestra.com/security/)
- [Trust centre](https://withmestra.com/trust/)
- [Sub-processors](https://withmestra.com/trust/subprocessors/)
- [Export your data or close your account](https://withmestra.com/docs/how-to/export-or-close/)
