Security

Security and reliability

Syleri uses signed-in access for private workspaces, server-side boundaries for sensitive actions, and production deployment controls. Sensitive service keys stay on the server and should never be committed to source control.

Authentication

Protected pages require a signed-in account, and sessions are handled through server-side safeguards.

Secret handling

Private service keys stay on the server and are never exposed through browser code.

Database isolation

Access policies are designed so users can only reach their own conversations, messages, files, memories, and settings.

Cloud deployment

Syleri is deployed with production environment controls and HTTPS at the domain level.

Server-side processing

Accounts, chat history, files, settings, and private processing are handled through protected server-side boundaries.

Responsible disclosure

Security issues should be reported privately with clear reproduction steps and impact before public disclosure.

Report a security issue

Include affected URL, reproduction steps, expected impact, and your contact email. Please avoid public disclosure until the issue has been reviewed.

Report privately