Security
How we protect your data
An overview of the practices that keep accounts, credentials, and player data separated and secure.
Account isolation
Every account's data — games, players, ledger, campaigns — is scoped at the database layer by account ID. Accounts never see each other's data, and each has its own API keys, branding, and game allowlists.
Credential storage
Upstream provider credentials (agent tokens and secrets) are encrypted at rest using AES-GCM before they ever touch the database, and are only decrypted in-memory when making an authenticated request to the provider. Admin interfaces only ever display a masked version.
Player-facing game sessions
Game sessions are served through a sandboxed iframe that blocks top-level navigation, so a game client can never redirect a player's browser away from your site without their explicit action.
Auditability
Administrative actions — account changes, credential updates, catalog and allowlist edits — are recorded in an audit log with the acting admin, the change, and a timestamp.
Reporting a concern
If you believe you've found a security issue, please reach out via the contact page rather than filing a public issue.