Encrypted provider keys
Owner-configured platform provider keys are encrypted before database storage. Customer provider-key storage is disabled in the customer dashboard.
Owner-configured platform provider keys are encrypted before database storage. Customer provider-key storage is disabled in the customer dashboard.
Logs, caches, API keys, tokens and settings are separated by company.
Provider keys used by the local tester remain on the customer’s own computer and are not uploaded to Varion.
Request metadata is logged; prompts and generated answers are not stored in normal request logs.
Public traffic is terminated through Caddy with automatic TLS.
Hashed Varion keys, team roles, rate limits, spending limits and optional IP allowlists.
Automatic database backups with owner-triggered backups available.
Unverified workflows remain passthrough instead of forcing compression.
Report security issues privately to security@varion.tech. Do not include live API keys in email.