Trust & architecture
How ArtInStack is structured
A high-level map of layers—from structured content through media, experiences, commerce, client delivery, and conservation fieldwork—plus the security, reliability, and operational posture serious studios and field organizations ask about before they standardize. The same footprint serves commerce studios and conservation orgs.
Ready to go deeper? Browse our documentation for feature guides and setup detail—no subscription required to explore.
Infrastructure blueprint
Your content, infrastructure, and commerce should belong entirely to you. ArtInStack organizes your digital asset workflows, server runtimes, and global print fulfillment into a highly secure, private network footprint—giving you enterprise-grade performance and absolute control over your digital borders without the vendor lock-in.
Product capabilities
- Print On DemandSell prints automatically
- Websites & PublishingPublish pages and stories
- PortfolioShowcase work beautifully
- Media & DeliveryUpload once, deliver everywhere
- Client DashboardBranded client proofing portals
- CoursesLessons and student access
- E-CommerceCheckout, orders, fulfillment
- Ad EmbedMonetize with display ads
- Affiliates IntegrationTrack partner commissions
- DonationsAccept supporter contributions
- CampaignsRun fundraising drives
- Impact MapSee reach by location
- Team & WorkflowCollaborate with clear roles
- WorkshopsSell workshop experiences
- EventsSessions and registrations
- Premium LightboxImmersive viewing experiences
- Field surveys & observationsStructured field records on media
- Camtrap DP exportPartner packages from the survey
- Digital ProductsSell files and access
- DownloadsGated high-resolution delivery
- Model ReleaseCapture model consent
- Gallery ApprovalClient selects and approves
- LicensingRights and usage terms
- Privacy & SecurityAccess and data controls
- Prepare / publish to GBIFHarvest packages under your Publisher
- Sensitive-species redactionFuzz or withhold coordinates by policy
- Automated EXIF extractionMetadata from camera files
- Geo taggingPin work on maps
- HTML5 Video PlayerCustomizable media player
- AnalyticsTraffic, sales, and engagement
Core technology
GrapesJSNext.js
TipTap
React
Scalable and reliable infrastructure for every site
Browsers and private object storage meet the CDN edge; HTTPS terminates on the ArtInStack application on Google Cloud, which renders experiences and talks to Directus over a private path. Directus is not a public surface—PostgreSQL on Google Cloud SQL sits beside it—while Stripe, print, email, ads, maps, and GBIF attach as third-party APIs at controlled seams.
Browser · TLS
Client
Visitors and operators use modern browsers; transport is encrypted end to end for app traffic.
R2 · Bunny.net
Object storage
Private buckets and streaming-friendly paths for originals, derivatives, and video—before public URLs are minted at the edge.
Cloudflare
CDN & edge
Image Resizing, edge cache, custom-domain SSL, and proxied DNS—public media and sites ride Cloudflare’s edge before traffic reaches the app.
Sites · portals · PDPs
Experiences
Rendered and cached through the application tier—visitors do not call Directus directly; HTML and APIs are composed server-side before responses leave GCP.
Next.js & APIs
ArtInStack
The product runtime on Google Cloud: server routes, APIs, uploads, commerce, and portals—surfaces combine GrapesJS and React where editors and blocks ship.
Content & config plane
Directus
Structured collections, permissions, and editorial workflows—not exposed on the public internet; the application tier mediates every read and write.
Google Cloud SQL
PostgreSQL
Relational storage for Directus and supporting services, provisioned as Cloud SQL inside the same private network posture.
HTTPS integrations
Third-party APIs
Stripe, print partners, Resend, ads, maps, and science registries attach at controlled seams with server-held secrets and CSP-aware embeds.
GBIF
Science registry
Conservation features call GBIF for taxon suggest; Creators prepare and optionally publish datasets under their own endorsed Publisher identity.
Uploads: images, video, PDFs, and documents—presigned where supported—create or update Directus records and storage keys before public URLs are minted.
Integrations & seams
Third parties attach with scoped keys, HTTPS, and CSP-aware embeds
Media & edge
- Cloudflare R2Private object storage for images, PDFs, and originals; presigned uploads and least-privilege keys.
- Bunny.netVideo pipeline—encoding and adaptive streaming paths used alongside still assets.
- Cloudflare CDN & edgeCache-friendly public URLs, image resizing (`/cdn-cgi/image/`) where enabled, and edge-adjacent delivery patterns.
- Image watermark workerOptional edge watermarking for public views when studio policy requires it.
Commerce & print
- StripeCard-present checkout, tax, and webhooks for order lifecycle.
- Stripe ConnectConnected accounts and destination charges where enabled—payouts stay aligned to seller identity.
- ProdigiPrint-on-demand fulfillment API and quote flows.
- GelatoAlternate print catalog and fulfillment integration.
Auth & email
- ResendTransactional email delivery for invitations, receipts, and verification flows over HTTPS.
- Cloudflare TurnstilePrivacy-friendly bot attestation on sensitive auth surfaces—reduces automated abuse without legacy CAPTCHA UX.
Maps & location
- Stadia MapsBasemap tiles for Impact Map and other location visualizations (production default).
- MapboxGeocoding and place search used with location features (tiles remain provider-selectable).
Monetization
- Google AdSenseOptional monetization embeds for publisher sites—loaded in sandboxed contexts with tightened CSP where configured.
- MediavineProgrammatic ad network integration for eligible sites—script allowlists scoped to vendor hosts.
- CarbonLightweight ad embed option with explicit script/connect/frame CSP guidance.
Science registry
- GBIFSpecies taxonomy suggest for conservation observations; optional dataset prepare/publish under the Creator’s endorsed Publisher.
Third-party scripts for ads load in isolated embed contexts where the product enforces CSP guidance; secrets stay server-side; map and ad providers only receive the tokens you configure in settings.
Trust, stated as facts
Straightforward claims you can explore in a trial or demo, then cross-check in our documentation when you want the full picture.
Data security
Client data sits behind portal and delivery boundaries—rooms and delivery surfaces are not anonymous public URLs by default. Media ships through CDN-backed, cache-friendly URLs and private object storage so global delivery stays aligned with your access model.
Secure uploads
Presigned upload flows and least-privilege storage patterns keep your asset graph scoped to the right actors and surfaces.
Private client portals
Access codes, expirations, and download policy give you controls suited to high-trust delivery workflows.
GDPR-style controls
Built with consent, access, and erasure in mind so your studio can grow into GDPR-style expectations—your counsel can help you map this to your DPA and how you configure the workspace.
Billing & payments
Checkout follows Stripe-hosted payment patterns—the same approach paying clients already trust for card data.
Geo privacy
Control where work appears on maps and public surfaces so geography tells the story you want—and lines up with how you already talk to clients about location data.
Granular permissions
Dashboard permissions map to who may change commerce, the builder, portals, and client delivery surfaces.
Revocable access
Expiring links, download controls, and portal lifecycle patterns support studios that need to tighten or end access over time.
Security, privacy, reliability, and compliance
A closer look at how we protect access to creative work, control what appears publicly, keep delivery fast at scale, and publish clear legal and vendor expectations—so you can compare options with confidence before you subscribe.
Who can reach your work—and through which doors. Client delivery, dashboard roles, commerce, and third-party clients each get explicit boundaries so sensitive creative assets are not treated like anonymous public files.
- Branded client portals — Present work in a dedicated client experience with access codes, expirations, and download rules suited to high-trust delivery—not anonymous public links by default.
- Custom domain HTTPS — HTTPS included: certificates are automatically issued and renewed for your configured domain at no extra charge. You do not purchase, upload, or renew a TLS certificate.
- Secure uploads — Presigned upload flows and least-privilege storage patterns keep your asset graph scoped to the right actors and surfaces.
- Protected video playback — Streaming links are time-limited and issued when a visitor or client is authorized to watch on your site, portals, or galleries—not as a permanent, copy-paste URL anyone can reuse.
- Roles & invitations — Granular permissions for who can touch commerce, the builder, portals, and delivery—plus invitations and delegation so day-to-day work does not require full admin access.
- Connected apps — Third-party clients (for example the official Lightroom publish service) authorize with scoped OAuth; you can review and revoke access any time from your workspace.
- Commerce trust — Checkout flows follow Stripe-hosted patterns so card data stays where paying clients already expect it, with clear ownership between your studio, your clients, and the platform.
- Maintenance & pauses — Put the public site into maintenance when you need a clean window to ship a rebrand or major change—while your team keeps working behind the scenes.
Next up: Capability Deep Dives
Map this architectural footprint directly to the workspace. Explore our specialized pillars—Websites & Publishing, Portfolio, Media, Conservation, Commerce, Delivery, and Team—to see how each infrastructure layer translates into the native product UI.
