Protection throughout the session
KeepMe uses opaque session capabilities, organization-scoped retailer access, private no-store image delivery, strict upload decoding, metadata removal, rate limits, provider budgets, encrypted object storage, and verified deletion.
Production controls
Live personal-image processing fails closed unless database, object-storage encryption, authentication, receipt-signing, cleanup, malware-scanning, and integrity-service settings are present. The controlled synthetic demo remains available, and sensitive values stay server-only.
Receipts and audit events
Integrity receipts contain digests of the approved contract and result and are signed. Operational logs exclude images, secrets, source filenames, provider result URLs, and direct identity attributes.
Report a concern
Do not include personal images, credentials, or exploit details in public reports. Use the security contact configured by the retailer operating this deployment.