Mestra resizes advertising masters into every format a campaign needs. This page describes how the service is built and run today. Where something is planned rather than in place, we say so.
Hosting and data residency
The service and database run in Sydney. Library files are stored in Cloudflare R2 with an Oceania location hint, which Cloudflare describes as best effort. Some data is processed or held overseas, as listed below and on the sub-processors page.
| Data | Where it lives |
|---|---|
| Application server | Fly.io, Sydney |
| Database | Neon Postgres on AWS ap-southeast-2, Sydney. Holds accounts, settings, run records, usage and the audit log. |
| Library files | Cloudflare R2 with an Oceania location hint. Cloudflare describes location hints as best effort, not a guarantee. |
| Traffic in transit | Cloudflare's global network |
| AI processing | United States |
| Sign-in and notice email | Postmark, United States |
| Payments | Stripe, United States and other countries. |
| Operational logs | Fly.io, kept for 7 days |
Encryption
- In transit: public traffic is HTTPS only (TLS 1.2 or later, with HSTS). Cloudflare reaches our server only through an encrypted tunnel, and the server connects to the database, file storage, AI provider and email service over TLS.
- Library files are encrypted by Mestra before they're stored, with a separate key for each organisation. Our storage provider only ever holds encrypted data. Those keys are themselves encrypted with a master key kept in our hosting platform's secret store. Because Mestra has to open files to deliver them to you, we can technically decrypt them: one person, the founder, has that access. It's protected by multi-factor authentication and used only to run the service or when you ask. The library is off unless your organisation turns it on.
- Database: other records rely on the database provider's encryption at rest.
- Sign-in tokens: sessions, sign-in links and app tokens are random, and only their hashes are stored.
Access control
- Roles: people join your organisation as owner, editor or viewer. Every request is scoped to one organisation, and removing someone or changing their role ends their sessions in that organisation at once.
- Sign-in: with an emailed link, Google or Microsoft (work and school accounts). An emailed link works once and expires after 15 minutes.
- Design apps: InDesign, Figma and Canva connect through a browser approval, so nobody pastes passwords or tokens.
- Audit log: sign-ins, membership and configuration changes and staff actions are recorded and kept for one year.
- Staff access: Mestra staff reach the admin console only through Cloudflare Access and their own sign-in. To help with a support request, a staff member can open your organisation as an owner would, for up to an hour, after recording a reason. They can't change roles, invite people, create download links or touch billing. Each session, its reason and every change made are recorded in your audit log, and owners can see them on the Activity page.
- Vendor accounts: multi-factor authentication is on for every hosting and infrastructure account.
AI processing and data use
Layouts are planned and reviewed by Anthropic (Claude API; currently Claude Opus 5.5). Each request sends the composition read from your master (copy, fonts, positions and image link names and paths), your format and brand settings and, for a review, a rendered preview image. Anthropic processes this in the United States.
Mestra doesn't store this working data, its prompts or the model's replies. Anthropic deletes API inputs and outputs within 30 days by default. Content flagged for a usage-policy violation may be kept for up to 2 years (classification scores up to 7 years), or longer where the law requires. Under Anthropic's commercial terms, customer content isn't used to train models. Mestra doesn't claim zero data retention.
Retention and deletion
- Mestra doesn't keep the artwork or copy it reads from your master. Settings you enter, such as campaign copy and logos, are kept until you delete them. If a trial or subscription ends, or an invoice is 14 days unpaid, your organisation becomes read-only. Unless you subscribe or pay the overdue invoice within 60 days, its content and settings are then deleted, and we keep only what our Privacy Policy describes. The optional file library is off by default. When an owner turns it on, files are kept for 30, 90 or 365 days and then deleted.
- Run records and usage counts are kept for the life of the organisation. The audit log is kept for one year.
- Owners and editors can delete settings, logos and library files at any time.
Data-handling details are available on request: email privacy@withmestra.com.
Breach notification
If a security incident affects your data, we'll tell you without undue delay, aiming for 72 hours from confirming it.
Data requests
Organisation owners can ask us to export or delete their organisation's data at any time: email privacy@withmestra.com.
Monitoring and status
UptimeRobot checks the service every 60 seconds, including sign-in. Live status and incident updates are at status.withmestra.com. Request logs carry no customer content. Mestra runs in a single region, aims to be available at all times and doesn't offer an SLA.
Engineering practice
Every change runs automated tests and vulnerability scans. Security-sensitive designs are reviewed before release.
Certifications
Mestra has no SOC 2 or ISO 27001 certification yet, and no independent audit or penetration test. We'd rather say so than imply otherwise. Our security pack and completed security questionnaire answers are available on request.
Security policies
Our security policies: Information security, Access control, Change management, Backup and recovery, Incident response, Vendor management and Vulnerability disclosure. Adopted October 2026 and reviewed every year. Copies are available on request: email security@withmestra.com. Vulnerability disclosure is public, below.
Responsible disclosure
If you think you've found a vulnerability, email security@withmestra.com. We'll reply within two business days. Our security.txt has the machine-readable details.
- Include what you found and where, steps to reproduce it, and the impact you expect. Encrypt sensitive details with our PGP key (fingerprint DEEB 19CE 4D4F 6669 FDAF 90D3 4B1D 3CFE B08D E03D, at /.well-known/pgp-key.txt). Please don't send customer data you've accessed: describe it instead.
- In scope: app.withmestra.com, the Mestra apps and withmestra.com. Don't test admin.withmestra.com or status.withmestra.com, and no denial-of-service, load testing or social engineering.
- Testing rules: use only accounts and organisations you own (ask us for a test organisation if you need one). Don't access, change or keep other customers' data: if you reach any, stop and tell us. Don't degrade the service for others.
- Timing: give us a reasonable time to fix the issue before you disclose it. Our target is 90 days, or sooner by agreement.
- Our commitments: we'll acknowledge your report, keep you updated, tell you when it's fixed and credit you if you'd like. We won't pursue legal action against good-faith research that follows this policy. We don't currently offer paid bounties.
Incident contact
Report a security incident to security@withmestra.com. Updates are posted at status.withmestra.com.