Security

Designed for protected API traffic

Encrypted provider keys

Owner-configured platform provider keys are encrypted before database storage. Customer provider-key storage is disabled in the customer dashboard.

Tenant isolation

Logs, caches, API keys, tokens and settings are separated by company.

No tester-key storage

Provider keys used by the local tester remain on the customer’s own computer and are not uploaded to Varion.

Safe logging

Request metadata is logged; prompts and generated answers are not stored in normal request logs.

HTTPS

Public traffic is terminated through Caddy with automatic TLS.

Access controls

Hashed Varion keys, team roles, rate limits, spending limits and optional IP allowlists.

Backups

Automatic database backups with owner-triggered backups available.

Safe fallback

Unverified workflows remain passthrough instead of forcing compression.

Responsible disclosure

Report security issues privately to security@varion.tech. Do not include live API keys in email.

A formal independent penetration test and security certification are not yet claimed.