Trust & architecture

How ArtInStack is structured

A high-level map of layers—from structured content through media, experiences, commerce, client delivery, and conservation fieldwork—plus the security, reliability, and operational posture serious studios and field organizations ask about before they standardize. The same footprint serves commerce studios and conservation orgs.

Ready to go deeper? Browse our documentation for feature guides and setup detail—no subscription required to explore.

Infrastructure blueprint

Your content, infrastructure, and commerce should belong entirely to you. ArtInStack organizes your digital asset workflows, server runtimes, and global print fulfillment into a highly secure, private network footprint—giving you enterprise-grade performance and absolute control over your digital borders without the vendor lock-in.

Product capability map: workspace pillars across libraries, integrations, and product features, including websites, portfolio, media, conservation and fieldwork, client portals, courses, commerce, and team workflow, built on GrapesJS, Next.js, TipTap, and React.
WebsitesPortfolioMediaConservationClient deliveryCoursesCommerceTeam

Product capabilities

  • Print On DemandSell prints automatically
  • Websites & PublishingPublish pages and stories
  • PortfolioShowcase work beautifully
  • Media & DeliveryUpload once, deliver everywhere
  • Client DashboardBranded client proofing portals
  • CoursesLessons and student access
  • E-CommerceCheckout, orders, fulfillment
  • Ad EmbedMonetize with display ads
  • Affiliates IntegrationTrack partner commissions
  • DonationsAccept supporter contributions
  • CampaignsRun fundraising drives
  • Impact MapSee reach by location
  • Team & WorkflowCollaborate with clear roles
  • WorkshopsSell workshop experiences
  • EventsSessions and registrations
  • Premium LightboxImmersive viewing experiences
  • Field surveys & observationsStructured field records on media
  • Camtrap DP exportPartner packages from the survey
  • Digital ProductsSell files and access
  • DownloadsGated high-resolution delivery
  • Model ReleaseCapture model consent
  • Gallery ApprovalClient selects and approves
  • LicensingRights and usage terms
  • Privacy & SecurityAccess and data controls
  • Prepare / publish to GBIFHarvest packages under your Publisher
  • Sensitive-species redactionFuzz or withhold coordinates by policy
  • Automated EXIF extractionMetadata from camera files
  • Geo taggingPin work on maps
  • HTML5 Video PlayerCustomizable media player
  • AnalyticsTraffic, sales, and engagement

Core technology

  • GrapesJS
  • Next.js
  • TipTap
  • React

Scalable and reliable infrastructure for every site

Browsers and private object storage meet the CDN edge; HTTPS terminates on the ArtInStack application on Google Cloud, which renders experiences and talks to Directus over a private path. Directus is not a public surface—PostgreSQL on Google Cloud SQL sits beside it—while Stripe, print, email, ads, maps, and GBIF attach as third-party APIs at controlled seams.

Layered diagram: client and adjacent object storage connect into a full-width Cloudflare CDN strip; HTTPS enters a Google Cloud Network box where experiences sit left of the branded application; a horizontal flow links the application to Directus, then Directus to PostgreSQL on Google Cloud SQL; GBIF science registry sits left of third-party vendor boxes below. A centered security chip above the tier summarizes TLS in transit, encryption at rest on storage, and Turnstile on sensitive auth.
Platform architecture: ArtInStack on Google Cloud with experiences, Directus, PostgreSQL on Cloud SQL, CDN edge, object storage, third-party APIs, and GBIF science registryTLS in transit; encryption at rest on storage;Turnstile on sensitive auth.ClientBrowser · TLSObject storageR2 · Bunny.netCDN & edge · CloudflareImage Resizing · Edge Cache · Custom Domain SSL · Proxied DNSHTTPSGoogle Cloud NetworkExperiencesSites · portals · PDPsArtInStackNext.js & APIs(GrapesJS · React)DirectusContent & config plane(Backend as a Service)PostgreSQLGoogle Cloud SQLScience registryTaxon suggest · publishThird-party applicationsStripeProdigiGelatoResendGoogle AdSenseStadia Maps
  • Browser · TLS

    Client

    Visitors and operators use modern browsers; transport is encrypted end to end for app traffic.

  • R2 · Bunny.net

    Object storage

    Private buckets and streaming-friendly paths for originals, derivatives, and video—before public URLs are minted at the edge.

  • Cloudflare

    CDN & edge

    Image Resizing, edge cache, custom-domain SSL, and proxied DNS—public media and sites ride Cloudflare’s edge before traffic reaches the app.

  • Sites · portals · PDPs

    Experiences

    Rendered and cached through the application tier—visitors do not call Directus directly; HTML and APIs are composed server-side before responses leave GCP.

  • Next.js & APIs

    ArtInStack

    The product runtime on Google Cloud: server routes, APIs, uploads, commerce, and portals—surfaces combine GrapesJS and React where editors and blocks ship.

  • Content & config plane

    Directus

    Structured collections, permissions, and editorial workflows—not exposed on the public internet; the application tier mediates every read and write.

  • Google Cloud SQL

    PostgreSQL

    Relational storage for Directus and supporting services, provisioned as Cloud SQL inside the same private network posture.

  • HTTPS integrations

    Third-party APIs

    Stripe, print partners, Resend, ads, maps, and science registries attach at controlled seams with server-held secrets and CSP-aware embeds.

  • GBIF

    Science registry

    Conservation features call GBIF for taxon suggest; Creators prepare and optionally publish datasets under their own endorsed Publisher identity.

Uploads: images, video, PDFs, and documents—presigned where supported—create or update Directus records and storage keys before public URLs are minted.

Integrations & seams

Third parties attach with scoped keys, HTTPS, and CSP-aware embeds

Media & edge

  • Cloudflare R2Private object storage for images, PDFs, and originals; presigned uploads and least-privilege keys.
  • Bunny.netVideo pipeline—encoding and adaptive streaming paths used alongside still assets.
  • Cloudflare CDN & edgeCache-friendly public URLs, image resizing (`/cdn-cgi/image/`) where enabled, and edge-adjacent delivery patterns.
  • Image watermark workerOptional edge watermarking for public views when studio policy requires it.

Commerce & print

  • StripeCard-present checkout, tax, and webhooks for order lifecycle.
  • Stripe ConnectConnected accounts and destination charges where enabled—payouts stay aligned to seller identity.
  • ProdigiPrint-on-demand fulfillment API and quote flows.
  • GelatoAlternate print catalog and fulfillment integration.

Auth & email

  • ResendTransactional email delivery for invitations, receipts, and verification flows over HTTPS.
  • Cloudflare TurnstilePrivacy-friendly bot attestation on sensitive auth surfaces—reduces automated abuse without legacy CAPTCHA UX.

Maps & location

  • Stadia MapsBasemap tiles for Impact Map and other location visualizations (production default).
  • MapboxGeocoding and place search used with location features (tiles remain provider-selectable).

Monetization

  • Google AdSenseOptional monetization embeds for publisher sites—loaded in sandboxed contexts with tightened CSP where configured.
  • MediavineProgrammatic ad network integration for eligible sites—script allowlists scoped to vendor hosts.
  • CarbonLightweight ad embed option with explicit script/connect/frame CSP guidance.

Science registry

  • GBIFSpecies taxonomy suggest for conservation observations; optional dataset prepare/publish under the Creator’s endorsed Publisher.

Third-party scripts for ads load in isolated embed contexts where the product enforces CSP guidance; secrets stay server-side; map and ad providers only receive the tokens you configure in settings.

Trust, stated as facts

Straightforward claims you can explore in a trial or demo, then cross-check in our documentation when you want the full picture.

Data security

Client data sits behind portal and delivery boundaries—rooms and delivery surfaces are not anonymous public URLs by default. Media ships through CDN-backed, cache-friendly URLs and private object storage so global delivery stays aligned with your access model.

Secure uploads

Presigned upload flows and least-privilege storage patterns keep your asset graph scoped to the right actors and surfaces.

Private client portals

Access codes, expirations, and download policy give you controls suited to high-trust delivery workflows.

GDPR-style controls

Built with consent, access, and erasure in mind so your studio can grow into GDPR-style expectations—your counsel can help you map this to your DPA and how you configure the workspace.

Billing & payments

Checkout follows Stripe-hosted payment patterns—the same approach paying clients already trust for card data.

Geo privacy

Control where work appears on maps and public surfaces so geography tells the story you want—and lines up with how you already talk to clients about location data.

Granular permissions

Dashboard permissions map to who may change commerce, the builder, portals, and client delivery surfaces.

Revocable access

Expiring links, download controls, and portal lifecycle patterns support studios that need to tighten or end access over time.

Security, privacy, reliability, and compliance

A closer look at how we protect access to creative work, control what appears publicly, keep delivery fast at scale, and publish clear legal and vendor expectations—so you can compare options with confidence before you subscribe.

Who can reach your work—and through which doors. Client delivery, dashboard roles, commerce, and third-party clients each get explicit boundaries so sensitive creative assets are not treated like anonymous public files.

  • Branded client portals — Present work in a dedicated client experience with access codes, expirations, and download rules suited to high-trust delivery—not anonymous public links by default.
  • Custom domain HTTPS — HTTPS included: certificates are automatically issued and renewed for your configured domain at no extra charge. You do not purchase, upload, or renew a TLS certificate.
  • Secure uploads — Presigned upload flows and least-privilege storage patterns keep your asset graph scoped to the right actors and surfaces.
  • Protected video playback — Streaming links are time-limited and issued when a visitor or client is authorized to watch on your site, portals, or galleries—not as a permanent, copy-paste URL anyone can reuse.
  • Roles & invitations — Granular permissions for who can touch commerce, the builder, portals, and delivery—plus invitations and delegation so day-to-day work does not require full admin access.
  • Connected apps — Third-party clients (for example the official Lightroom publish service) authorize with scoped OAuth; you can review and revoke access any time from your workspace.
  • Commerce trust — Checkout flows follow Stripe-hosted patterns so card data stays where paying clients already expect it, with clear ownership between your studio, your clients, and the platform.
  • Maintenance & pauses — Put the public site into maintenance when you need a clean window to ship a rebrand or major change—while your team keeps working behind the scenes.

Next up: Capability Deep Dives

Map this architectural footprint directly to the workspace. Explore our specialized pillars—Websites & Publishing, Portfolio, Media, Conservation, Commerce, Delivery, and Team—to see how each infrastructure layer translates into the native product UI.