Security
- API keys are stored as SHA-256 hashes; the plaintext key is shown once.
- Tool inputs are hashed on the client or server for loop detection; prompts and outputs are never stored.
- Evidence file checks run on your machine; only a boolean is transmitted.
- Every finished run gets a hash that is chained per day and anchored in Bitcoin via OpenTimestamps, so a record cannot be altered afterwards without it showing; see verifiable runs. An auditor can verify a run with a standalone script and
ots verify, without trusting us: how. - All traffic is TLS via Cloudflare; infrastructure in the EU (Netherlands).
- Per-key rate limits; alert credentials (Telegram token, webhook URL) are stored per account and used only to deliver your alerts.
- Report vulnerabilities via the contact form (topic: security), see security.txt.