> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Delivery security

> Restrict Cloud CDN requests by geography, IP, referrer, user agent, and signed URL.

Cloud CDN security controls are distribution-level access policies. They supplement application authorization; they do not replace it.

## Access-control lists

Country, IP, referrer, and user-agent policies support two modes:

* **Allow all except listed:** block the listed values.
* **Deny all except listed:** allow only the listed values.

Country values use validated country codes. IP entries should be explicit addresses or networks accepted by the configuration UI. Test deny-by-default policies from an allowed and a disallowed network before production rollout.

## Signed URLs

Secure-key protection requires a signing key and token type. Token type can include or exclude the client IP from validation.

<Warning>
  A signing key grants access to protected URLs. Generate it outside Aptranet, store it as a secret, and never expose it in client code or documentation.
</Warning>

## Defense in depth

* Validate authorization at the application origin.
* Keep origin services patched and restrict direct access where possible.
* Use HTTPS and origin certificate validation.
* Avoid caching denial or authenticated responses under a shared key.
* Review ACL values after network, vendor, or workforce changes.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.