Security and privacy

What the platform does today to protect your account, your keys and your data.
Your account, with a boundary around it

API keys

A key is shown once, when it is created. We keep only a SHA-256 hash of it and its first characters, so a key cannot be read back, not even by us.A revoked key stops working within 30 seconds.

Your organization's data stays yours

Every request is checked against the organization of the signed-in member. A record that belongs to another organization is treated as if it did not exist.

Roles enforced on the server

Owner, Billing, Developer and Read-only members see and do only what their role allows. The check happens on the server, not just on the screen.

Request content is not stored

We do not store the prompts you send or the answers you receive. For each call we record the model, the number of tokens, whether it succeeded, how long it took and the cost. When a provider rejects a call, we keep the first 1,000 characters of its error message, which some providers fill with part of the request.

Card details

The card number and security code are typed into the payment gateway's secure field and never reach our servers.

Passwords

Passwords have at least 12 characters and are stored only as hashes. Resetting your password ends every session of your account.

Build what comes next.

Request an invitation and tell the team what you want to build.