Security

The practices we follow to keep your account and data safe.

Data in transit

All traffic between your browser and PromptX is encrypted using TLS.

Authentication

Sign-in is handled by a dedicated authentication provider supporting modern protections such as multi-factor authentication and SSO/SAML on eligible plans. We never store your password.

API keys

API keys are shown once at creation and stored only as a hashed value — we cannot recover the original. You can revoke a key at any time, which immediately invalidates it.

Access & isolation

Access to data is scoped by team and role, following the principle of least privilege. We rely on reputable infrastructure providers to host the service.

Reporting a vulnerability

If you believe you have found a security issue, please email contact@promptx.xevos.dev with details. We appreciate responsible disclosure and will respond as quickly as we can.