Security at Starlight

Your most sensitive work deserves more than the basics.

Starlight protects identity records, health information, consent, contracts, and production activity with several layers of safeguards. If one layer is challenged, others are still standing behind it.

  • Independent web application test completed
  • Sensitive files encrypted
  • Multi-factor sign-in protection
  • Uploaded files inspected
  • Permission-based access controls
  • Security-relevant activity logged
Protection for every workspace

One high standard, tailored to how you work.

Creators and studios use different tools, so each platform adds protections around its most sensitive actions.

Creator platform

Personal records stay personal.

  • Stronger sign-in: authenticator-app MFA, email verification, passkeys, and strong-password checks help protect creator accounts.
  • Encrypted records: sensitive uploads, signed documents, and connected-service secrets are encrypted when stored.
  • Safer sharing: identity, STI, and consent records are returned only through authorized, limited-access workflows.
  • Inspected uploads: images and PDFs are checked for malware; PDFs are rebuilt into safer copies before delivery.
Studio platform

Teams see only what their role needs.

  • Permission-based access: production, legal, finance, payment, performer, and compliance actions are separated by role.
  • Protected team access: Microsoft SSO and MFA strengthen staff sign-in, while organization boundaries keep studio data separated.
  • Accountable activity: important actions and access to sensitive talent records are written to audit logs.
  • Separated talent portal: performers receive a limited, MFA-protected view of only the records connected to them.
Going beyond the checkbox

Sensitive files never get a casual pass.

PDF uploads are handled by a separate, locked-down scanning service. It checks the complete file, malware-scans it, converts every page into a clean new PDF, verifies that copy, and scans it again. The main platform stores the sanitized copy, not the quarantined original.

If a required scanner or protection is unavailable, the upload is rejected instead of being accepted without inspection. Production startup also stops when required security settings are missing.

  1. 1
    QuarantineThe upload is kept away from the main app.
  2. 2
    InspectThe full file is checked for malware and risky features.
  3. 3
    RebuildEvery page becomes a clean, flattened PDF.
  4. 4
    Verify againOnly the checked replacement reaches protected storage.
Specific threats

What our safeguards are designed to defend against.

The names can sound technical. Here is what they mean and how Starlight reduces the risk.

XSS

Malicious scripts on a page

Output escaping and a strict Content Security Policy help stop submitted text from turning into code in someone else’s browser.

CSRF

Forged actions from another site

Protected forms require a secret, session-specific token, so another website cannot quietly submit an account action on your behalf.

SQLi

Database command injection

Server-side validation and parameterized database queries keep submitted values separate from database instructions.

SSRF

Probing private systems through our server

Outbound links are checked to block local, private, link-local, and suspicious destinations before a server request is allowed.

Files

Malware and dangerous uploads

File type, size, content, and malware checks run before acceptance. High-risk PDFs are isolated, rebuilt, and scanned twice.

Auth

Password guessing and account takeover

MFA, passkeys, bot challenges, strong-password rules, short-lived codes, and layered rate limits make repeated sign-in attacks harder.

UI

Clickjacking and content-type tricks

Browser security headers limit who can frame Starlight and prevent browsers from guessing a file type that was never intended.

Data

Interception and session theft

HTTPS enforcement, HSTS, secure cookies, HttpOnly protection, and same-site cookie rules help protect data and signed-in sessions.

APIs

Fake callbacks and integration abuse

Webhook signatures, OAuth state and nonce checks, bounded request sizes, and verified redirect destinations protect connected services.

Independent testing

BreachLock tested our public web application.

BreachLock Inc. independently completed a web application penetration test of www.starlight-secure.com. The test ran from July 10 through July 17, 2026.

A penetration test has security specialists approach the application like an attacker would: looking for weaknesses in the website, accounts, and exposed systems so they can be addressed.

Our penetration test results placed Starlight in the top percentile of assessed applications. Every vulnerability identified during testing has been patched, and our controls remain under continuous monitoring so new risks can be found and addressed quickly.

View BreachLock attestation