Trust

Trust centre

Mestra Labs Pty Ltd, ABN 73 702 936 356, Sydney. Last updated 4 October 2026.

Mestra resizes advertising masters into every format a campaign needs. This page describes how the service is built and run today. Where something is planned rather than in place, we say so.

Hosting and data residency

The service and database run in Sydney. Library files are stored in Cloudflare R2 with an Oceania location hint, which Cloudflare describes as best effort. Some data is processed or held overseas, as listed below and on the sub-processors page.

DataWhere it lives
Application serverFly.io, Sydney
DatabaseNeon Postgres on AWS ap-southeast-2, Sydney. Holds accounts, settings, run records, usage and the audit log.
Library filesCloudflare R2 with an Oceania location hint. Cloudflare describes location hints as best effort, not a guarantee.
Traffic in transitCloudflare's global network
AI processingUnited States
Sign-in and notice emailPostmark, United States
PaymentsStripe, United States and other countries.
Operational logsFly.io, kept for 7 days

Encryption

  • In transit: public traffic is HTTPS only (TLS 1.2 or later, with HSTS). Cloudflare reaches our server only through an encrypted tunnel, and the server connects to the database, file storage, AI provider and email service over TLS.
  • Library files are encrypted by Mestra before they're stored, with a separate key for each organisation. Our storage provider only ever holds encrypted data. Those keys are themselves encrypted with a master key kept in our hosting platform's secret store. Because Mestra has to open files to deliver them to you, we can technically decrypt them: one person, the founder, has that access. It's protected by multi-factor authentication and used only to run the service or when you ask. The library is off unless your organisation turns it on.
  • Database: other records rely on the database provider's encryption at rest.
  • Sign-in tokens: sessions, sign-in links and app tokens are random, and only their hashes are stored.

Access control

  • Roles: people join your organisation as owner, editor or viewer. Every request is scoped to one organisation, and removing someone or changing their role ends their sessions in that organisation at once.
  • Sign-in: with an emailed link, Google or Microsoft (work and school accounts). An emailed link works once and expires after 15 minutes.
  • Design apps: InDesign, Figma and Canva connect through a browser approval, so nobody pastes passwords or tokens.
  • Audit log: sign-ins, membership and configuration changes and staff actions are recorded and kept for one year.
  • Staff access: Mestra staff reach the admin console only through Cloudflare Access and their own sign-in. To help with a support request, a staff member can open your organisation as an owner would, for up to an hour, after recording a reason. They can't change roles, invite people, create download links or touch billing. Each session, its reason and every change made are recorded in your audit log, and owners can see them on the Activity page.
  • Vendor accounts: multi-factor authentication is on for every hosting and infrastructure account.

AI processing and data use

Layouts are planned and reviewed by Anthropic (Claude API; currently Claude Opus 5.5). Each request sends the composition read from your master (copy, fonts, positions and image link names and paths), your format and brand settings and, for a review, a rendered preview image. Anthropic processes this in the United States.

Mestra doesn't store this working data, its prompts or the model's replies. Anthropic deletes API inputs and outputs within 30 days by default. Content flagged for a usage-policy violation may be kept for up to 2 years (classification scores up to 7 years), or longer where the law requires. Under Anthropic's commercial terms, customer content isn't used to train models. Mestra doesn't claim zero data retention.

Retention and deletion

  • Mestra doesn't keep the artwork or copy it reads from your master. Settings you enter, such as campaign copy and logos, are kept until you delete them. If a trial or subscription ends, or an invoice is 14 days unpaid, your organisation becomes read-only. Unless you subscribe or pay the overdue invoice within 60 days, its content and settings are then deleted, and we keep only what our Privacy Policy describes. The optional file library is off by default. When an owner turns it on, files are kept for 30, 90 or 365 days and then deleted.
  • Run records and usage counts are kept for the life of the organisation. The audit log is kept for one year.
  • Owners and editors can delete settings, logos and library files at any time.

Data-handling details are available on request: email privacy@withmestra.com.

Breach notification

If a security incident affects your data, we'll tell you without undue delay, aiming for 72 hours from confirming it.

Data requests

Organisation owners can ask us to export or delete their organisation's data at any time: email privacy@withmestra.com.

Monitoring and status

UptimeRobot checks the service every 60 seconds, including sign-in. Live status and incident updates are at status.withmestra.com. Request logs carry no customer content. Mestra runs in a single region, aims to be available at all times and doesn't offer an SLA.

Engineering practice

Every change runs automated tests and vulnerability scans. Security-sensitive designs are reviewed before release.

Certifications

Mestra has no SOC 2 or ISO 27001 certification yet, and no independent audit or penetration test. We'd rather say so than imply otherwise. Our security pack and completed security questionnaire answers are available on request.

Request the security pack

Security policies

Our security policies: Information security, Access control, Change management, Backup and recovery, Incident response, Vendor management and Vulnerability disclosure. Adopted October 2026 and reviewed every year. Copies are available on request: email security@withmestra.com. Vulnerability disclosure is public, below.

Responsible disclosure

If you think you've found a vulnerability, email security@withmestra.com. We'll reply within two business days. Our security.txt has the machine-readable details.

  • Include what you found and where, steps to reproduce it, and the impact you expect. Encrypt sensitive details with our PGP key (fingerprint DEEB 19CE 4D4F 6669 FDAF 90D3 4B1D 3CFE B08D E03D, at /.well-known/pgp-key.txt). Please don't send customer data you've accessed: describe it instead.
  • In scope: app.withmestra.com, the Mestra apps and withmestra.com. Don't test admin.withmestra.com or status.withmestra.com, and no denial-of-service, load testing or social engineering.
  • Testing rules: use only accounts and organisations you own (ask us for a test organisation if you need one). Don't access, change or keep other customers' data: if you reach any, stop and tell us. Don't degrade the service for others.
  • Timing: give us a reasonable time to fix the issue before you disclose it. Our target is 90 days, or sooner by agreement.
  • Our commitments: we'll acknowledge your report, keep you updated, tell you when it's fixed and credit you if you'd like. We won't pursue legal action against good-faith research that follows this policy. We don't currently offer paid bounties.

Incident contact

Report a security incident to security@withmestra.com. Updates are posted at status.withmestra.com.