Current safeguards
- Encrypted transport for production web, storage, and compute connections.
- Session-based authorization and ownership checks on protected project and run routes.
- API keys stored as hashes and displayed in plaintext only once when created.
- Short-lived upload URLs and scoped service credentials.
- Role-based administration, rate and budget controls, logging, health checks, and automated failure recovery.
- Project deletion and scheduled cleanup for abandoned and expired stored data.
Shared responsibility
No system is perfectly secure. Use data minimization and de-identification, protect account credentials, rotate exposed API keys, validate downloads, and do not submit data prohibited by our policies.
Report a vulnerability
Send a concise report to kai@psyproxy.ai with the affected URL, impact, and reproducible steps. Do not access other users' data, degrade service, use social engineering, or publish a vulnerability before we have a reasonable opportunity to investigate.
These reporting expectations are also part of the Terms of Service.
