Skip to Content
OperationsSecurity & privacy

Security and privacy

Credential boundaries

CredentialClassificationStorage
eng_app_… app keypublishable identifierapplication build configuration
engk_… access keyserver secretbackend secret manager
installation/revocation/recovery credentialsclient secretSDK-managed platform storage
FCM service account / APNs keyprovider secretencrypted Engage configuration
engwhsec_… webhook secretintegration secretwebhook service secret manager

Never use an app key as authorization. Never expose an access/provider/webhook key to a client.

Environment isolation

Use distinct environment app keys and access keys. Prefer distinct Firebase projects, app identifiers, and provider credentials for development, staging, and production. Validate the environment/app name in CI build configuration.

Identity

The SDK cannot claim a profile external ID directly. Binding uses a short-lived code and a trusted server transition. Derive the external ID from authenticated backend context.

Data minimization

  • Track only attributes and events required for a documented product purpose.
  • Avoid secrets, credentials, raw payment data, and unnecessary sensitive categories.
  • Define retention for events, profiles, exports, diagnostics, and delivery payloads.
  • Restrict workspace roles and export access.
  • Audit publishing, sends, credential management, privacy actions, and security changes.

System permission, Engage global push opt-in, subscription-list/channel choice, runtime SDK features, and privacy opt-out are distinct controls. The most restrictive applicable state wins.

Privacy workflows

SDK opt-out stops normal audience/analytics behavior according to policy. Explicit wipe clears local Engage state and converges remote revocation. Backend privacy requests support access/export and deletion workflows with durable status.

Logout is not deletion. Do not call privacy wipe on ordinary logout unless that is the explicit legal/product meaning.

Engage privacy operations view with access and deletion requests, durable status, scope, ownership, and audit information
Privacy requests are durable, auditable workflows rather than immediate UI-only mutations.
Engage workspace security configuration with identity connections, session controls, MFA policy, and security state
Workspace identity and session controls protect the operators who can publish content, send messages, and access audience data.

Application security

Register custom action handlers as trusted boundaries: validate argument type and destination, require current authentication/authorization, and reject unsafe actions. Server-authored DivKit must not bypass application authorization for protected operations.