Security and data
Trust boundaries, user isolation and provider residency.
Responsibilities of both systems
Pura protects its provider credentials and the internal account key, checks entitlements and enforces limits. Your app protects local sessions, client secrets, OAuth tokens and signing secrets; it must not give one user another user’s connection.
Browser and backend
For a confidential SaaS keep tokens on the backend and use a protected app session toward the browser. Do not put client secrets in bundles, NEXT_PUBLIC variables, HTML or localStorage. Public clients have no secret: their storage strategy must account for XSS and token lifetime.
Residency and evidence
EU selection happens in the gateway and deployment policies. Compliance metadata comes from the original provider transport, not an app-controlled field. A geographically European endpoint alone does not certify where a Global model executes a request.
Retention and logs
The subscription ledger stores request identity, model, internal cost and timestamps for accounting and audit. It is not a prompt or audio archive. Consult Pura Docs Data retention and EU residency pages for applicable terms and provider processing.
Webhook receiver
Verify signatures before parsing and bind app and user to existing mappings. Reject unsupported versions and credential fields even if signed. The SDK applies these checks; your store applies atomicity, ordering and mapping isolation.