Server-only secrets
Provider, database, billing, and AI credentials are never included in browser bundles.
Trust centre
The platform separates provider credentials, customer identity, billing state, prediction records, and public delivery surfaces.
Provider, database, billing, and AI credentials are never included in browser bundles.
Stripe webhook signatures are verified and event identities are recorded idempotently.
Syndicate keys are displayed once and persisted as SHA-256 hashes.
AI prompts contain normalized race inputs, not provider credentials or customer billing details.
Account quotas, request limits, and AI spending ceilings constrain automated usage.
Input hashes, model IDs, prompt versions, and generation times make records auditable.
Do not include credentials, personal information, or exploit payloads in public channels. A dedicated external vulnerability-intake address has not yet been published; until it is, avoid testing production beyond your own account and normal documented interfaces.
No website can make an absolute security guarantee. This page documents intended controls, not a certification, penetration-test claim, bug-bounty programme, or promise that every class of vulnerability has been eliminated.