- Provider keys are held server-side, never sent to the browser and never printed into a run log.
- Sessions are HttpOnly cookies. Workflow, execution and usage data is scoped to the owning account by the backend, not by the interface.
- Outbound HTTP steps run behind an allowlist that blocks requests to internal addresses.
Security
What we do with the keys you give us.