Back to Home
SECURITY ARCHITECTURE

Security Architecture & Transparency

How Diskey protects your Discord bot credentials with zero-knowledge database design and multi-layered encryption.

Zero Token Storage

Diskey does not persist your bot token to any SQL/NoSQL database. No credential records are ever written to server disk.

JWE AES-256-GCM Encryption

Sessions are sealed using authenticated JSON Web Encryption (JWE) with algorithm A256GCM backed by server environment secrets.

Automatic Log Redaction

Sanitization filters scrub token substrings from application logs and error responses, guaranteeing Discord tokens remain [REDACTED].

httpOnly & SameSite Cookies

Session cookies enforce httpOnly and sameSite=lax flags, isolating raw tokens from browser scripts and mitigating XSS risks.

Direct Server-to-Server Relay

All requests to Discord REST API v10 are executed server-side via Next.js Route Handlers. Client browsers never make direct token-bearing calls to Discord.

Security Architecture | Diskey Apps