Security
- API keys are stored as SHA-256 hashes; the plaintext key is shown once.
- Tool inputs are hashed on the client or server for loop detection; prompts and outputs are never stored.
- Evidence file checks run on your machine; only a boolean is transmitted.
- All traffic is TLS via Cloudflare; infrastructure in the EU (Netherlands).
- Per-key rate limits; alert credentials (Telegram token, webhook URL) are stored per account and used only to deliver your alerts.
- Report vulnerabilities to [email protected] — see security.txt.