Security and privacy
Credential boundaries
| Credential | Classification | Storage |
|---|---|---|
eng_app_… app key | publishable identifier | application build configuration |
engk_… access key | server secret | backend secret manager |
| installation/revocation/recovery credentials | client secret | SDK-managed platform storage |
| FCM service account / APNs key | provider secret | encrypted Engage configuration |
engwhsec_… webhook secret | integration secret | webhook service secret manager |
Never use an app key as authorization. Never expose an access/provider/webhook key to a client.
Environment isolation
Use distinct environment app keys and access keys. Prefer distinct Firebase projects, app identifiers, and provider credentials for development, staging, and production. Validate the environment/app name in CI build configuration.
Identity
The SDK cannot claim a profile external ID directly. Binding uses a short-lived code and a trusted server transition. Derive the external ID from authenticated backend context.
Data minimization
- Track only attributes and events required for a documented product purpose.
- Avoid secrets, credentials, raw payment data, and unnecessary sensitive categories.
- Define retention for events, profiles, exports, diagnostics, and delivery payloads.
- Restrict workspace roles and export access.
- Audit publishing, sends, credential management, privacy actions, and security changes.
Consent layers
System permission, Engage global push opt-in, subscription-list/channel choice, runtime SDK features, and privacy opt-out are distinct controls. The most restrictive applicable state wins.
Privacy workflows
SDK opt-out stops normal audience/analytics behavior according to policy. Explicit wipe clears local Engage state and converges remote revocation. Backend privacy requests support access/export and deletion workflows with durable status.
Logout is not deletion. Do not call privacy wipe on ordinary logout unless that is the explicit legal/product meaning.


Application security
Register custom action handlers as trusted boundaries: validate argument type and destination, require current authentication/authorization, and reject unsafe actions. Server-authored DivKit must not bypass application authorization for protected operations.