What operates today
The public website is hosted through Cloudflare. There are no customer accounts, API keys, paid jobs or stored customer API results. Interactive examples run locally in the browser. Optional analytics follows the website privacy notice.
Planned API controls
The service design requires authentication before access to task state, tenant isolation for results, scoped credentials, revocation and spending limits. API keys must not appear in URLs, public examples or support messages. These are release requirements; this page does not claim a running implementation, completed penetration test or security certification.
The data-retention design defaults to seven days for results and 30 days for request logs, with shorter result retention available to customers. Runtime settings must be verified before API access opens. See data practices and service providers for the current boundary.
Report a vulnerability
Email [email protected] with the affected URL, a concise description and minimal reproduction steps. Use a subject beginning with “Security report”. Do not send passwords, API keys or another person’s private data; redact any accidentally exposed material.
Do not access other users’ data or disrupt the service to demonstrate a finding. We do not currently publish a bounty program, guaranteed response time or contractual security SLA. General product questions belong on the contact page.