Account and API access
Dashboard authentication is handled by Auth0. Organization roles control what teammates can access, and scoped API keys let you give each application only the permissions it needs.
- Create separate keys for different applications and environments.
- Grant access to specific actions, such as creating images without deleting them or changing storage settings.
- Disable keys and revoke connected MCP sessions from your dashboard.
MCP connections use OAuth. You review the requested access before approving it, and the connection stays within your organization role and granted permissions.
Credentials and secrets
Save proxy and storage credentials once. Image requests reference the saved configuration by ID, so applications don't need to pass those secrets with every render.
Amazon S3 destinations use IAM role access instead of long-lived AWS access keys. Other storage providers and authenticated proxies use credentials supplied during setup.
Secrets are generated using cryptographically secure randomness, and runtime secrets are managed through AWS Secrets Manager. Keep your HCTI API credentials on the server, in your own secret-management system.
Data protection
We use PlanetScale and Amazon DynamoDB for database storage. Data is encrypted at rest and in transit.
Image storage and retention
HCTI provides hosted image URLs and CDN delivery. Paid plans retain generated images while your account remains active, and you can delete images through the API.
For images you want to keep in your own storage, configure a custom storage destination. With Disable HCTI Storage enabled, HCTI processes the render but doesn't retain the rendered file or serve it through a public HCTI image URL. Render settings and metadata are still retained.
Learn more about storage destinations.
Infrastructure and service health
Production services run on AWS, with Cloudflare at the edge. Our API and dashboard use HTTPS, and we use health checks and monitoring to track service availability.
Access to infrastructure resources is controlled through short-lived SSO sessions. Credentials follow least-privilege access: each person or service receives only the permissions needed for its work.
The status page publishes service status and incident history.
Payments
We use Chargebee for subscription billing and its hosted pages to collect payment details. Your card details go directly to Chargebee's payment flow and never pass through or get stored by HCTI. We receive the billing and subscription information needed to manage your account.
Fit your deployment workflow
Use our Terraform or Pulumi providers to manage templates, API keys, proxies, and storage destinations alongside your application infrastructure. Keep configuration in version control, review changes, and use separate keys and resources for each environment.
See the infrastructure-as-code guide and permission controls.
Questions and security reports
Email support@htmlcsstoimage.com with security questions or a suspected vulnerability. For a vulnerability report, include the affected endpoint and steps to reproduce it.
See our privacy policy and terms of service for information about how we handle your data and provide the service.