Skip to content

Security

This page summarizes the security expectations that matter to customers. It does not list internal implementation details.

  • The raw API key is shown only once.
  • Revoked keys stop working immediately.
  • Passwords, sessions, and sensitive access details are not exposed in user-facing screens.
LayerImplementation
TransportAll traffic uses HTTPS
AuthenticationSeparate secure flows for dashboard sessions and API keys
Account controlsAPI keys, usage tracking, and balance actions are managed in the account dashboard
Abuse protectionValidation, rate limiting, and misuse controls are applied

Data handling expectations are stated on model pages and formal legal notices. Before sending sensitive content, review the selected model’s data path and provider terms.

For models explicitly marked as hosted in Türkiye, requests are processed on LLMTR infrastructure in Türkiye. For third-party or foreign-provider models, the data path depends on the selected provider; review the model detail page before production use.

For formal legal notices, see the Privacy Policy and the KVKK Disclosure Notice.

If you discover a security problem, contact us through our support channels.