Security
We serve your images from your brand — so we treat every fetch as hostile
CDN.MN fetches images from origins you choose and delivers them under a hostname that represents you. That makes safety the product, not a feature bolted on. Here is how we protect your origin, your tenants, and your content.
Origin ownership is verified — and never assumed
A domain must be verified before we fetch anything from it, and we re-check ownership on a schedule so a lapsed or transferred domain stops being served. Verifying a domain never grants rights to content you don’t own.
Every origin fetch is validated at connection time
We resolve each origin’s address and refuse connections to private, internal, or reserved network ranges — and we re-validate on every redirect. A verified domain that later points at an internal address simply cannot be reached through us.
Tenants are isolated by a collision-proof cache identity
Every cached image is scoped to its tenant and to every parameter that affects the output. One customer’s content can never be addressed, or served, under another’s.
Fail closed at the edge
An unknown hostname, a suspended account, or a lookup error returns “not found” — never a fallback to some default origin. The safe answer is always the default.
Encrypted in transit, with managed certificates
Your CDN hostname is served over HTTPS with a managed certificate. There is nothing to provision and no certificate to renew.
Passwordless sign-in, revocable sessions
You sign in with an email code — no passwords to leak. Codes are stored only as a keyed hash and expire quickly; sessions are opaque, server-side tokens we can revoke instantly.
Take content down in seconds
Suspending a hostname, a site, or an account stops delivery within seconds across the global edge network — the control an operator needs the moment something is wrong.
Abuse-resistant by design
Per-tenant and per-IP rate limits, a bounded set of image variants, and a fixed per-site quality keep one bad actor from turning the service into a cost or abuse vector for everyone else.
Found something? Report it to security@cdn.mn. See also our Acceptable Use Policy and Privacy Policy.