Security

Security

Practical controls on the site and product — and a clear path to report issues.

The site

TLS on eyeban.ir, CSRF on forms, escaped templates, and a content security policy on this site.

Keys

No secrets in frontend assets. Default model API keys stay on the server (api.eyeban.ir). Optional desktop BYOK keys are stored in the OS secure store and sent only with proxied Agent requests — never baked into the website.

The agent

Agent tool use is gated by permissions (Ask / Allow safe / Allow all). Dependency updates and a written incident path continue as the product matures.

Practices we hold ourselves to

TLS, CSRF, escaped templates, and a content security policy on this site. Model keys stay on the server. Agent tools follow permission levels.

Report suspected vulnerabilities through the contact form with the security topic, with enough detail to reproduce. Do not attach customer source code unless we ask for a minimal sample. Formal third-party attestations will be listed here only when we hold them.