Security

Specific controls without vague badges

These are the protections implemented today. We do not claim certifications or guarantees we have not earned.

Sessions

Authentication is kept in secure, httpOnly cookies so browser scripts cannot read the session token.

Customer API keys

Full API keys are shown only when created. The service stores a one-way hash for later verification.

Upstream credentials

Supply credentials are encrypted before they are written to the database and are never returned through customer APIs.

Prepaid credit

Wallet credit is added only after the payment provider confirms the crypto invoice. Request charges are recorded in an append-only ledger.

Report a concern

Found a security issue?

Contact support