Docs / Help
Security
How keys, data and access are handled, and what to do on your side.
What we do
- API keys are stored only as a one-way fingerprint. We cannot read your key back.
- All traffic is encrypted (HTTPS).
- A key can only read its own workspace's jobs and data.
- Sign-in uses a one-time emailed code, with no password to steal.
- Every sensitive action (keys, people, style, decisions) is recorded in the activity log.
What you do
- Keep keys on servers, never in pages, apps or public code.
- Use one key per system so you can revoke one without breaking others.
- Remove people the day they leave.
- Review the activity log from time to time.
Your text
Text you send is used to run your check and to keep a record of it. Do not send passwords, personal ID numbers or private source details. If a story depends on a confidential source, remove identifying details before you check it.
Reporting a problem
If you believe you have found a security problem, do not post details in the community. Contact PIJAlance through pijalance.com and say it is a security report.