Security
Credentials
- Passwords hashed with bcrypt (cost 12)
- API keys: 192-bit random, stored as SHA-256 only, shown once at creation
- Sessions: HttpOnly, SameSite=Lax, Secure cookies, HS256-signed JWTs
- Logout and password change bump session version and invalidate outstanding tokens
Payments
Balance is posted after PayPal captures payment, or after a confirmed bank transfer when that rail is enabled. Ledger writes are idempotent per external payment id. We issue an invoice and email it after a paid top-up. An open PayPal dispute freezes further spend until it is resolved.
Platform controls
- TLS with HSTS between your application and the gateway
- TLS from the gateway to the GPU as well, pinned to our own certificate authority and terminating inside the inference process itself. There is no tunnel vendor or reverse-proxy middlebox in the path, and the gateway refuses to send prompts over plaintext to public addresses
- Security headers (CSP, frame-ancestors none, nosniff)
- Per-key rate limits and optional monthly spend caps
- API requests are proxied to the inference backend and never written to our database, only token counts for billing
- Inference engines run with request logging disabled, so prompts don't land in server logs either
Responsible disclosure
Report vulnerabilities to support@tokenkiln.comwith reproduction steps. Do not access other customers' data; use your own account for testing.