Security

Protecting customer data is part of the service.

Jylus applies layered controls across identity, tenant access, transport, service operation, and disclosure response.

Identity and access

Scoped API keys, server-side sessions, email verification, passkeys, and multi-factor authentication protect account and administrative access.

Application controls

Same-origin mutation checks, CSRF validation, strict input schemas, rate limits, no-store handling, and restrictive browser security headers reduce common web attack paths.

Data protection

Tenant-scoped credentials and queries, encrypted transport, controlled service identities, and auditable account actions support workspace isolation.

Operational response

Jylus monitors service health, records security-relevant events, and maintains private channels for vulnerability and incident reporting.

Coordinated disclosure

Report a security issue privately.

Email security@jylus.ai with the affected endpoint, reproduction steps, impact, and a safe contact method. Do not include customer data, credentials, or secrets.

Jylus will acknowledge reports, assess severity and scope, coordinate remediation, and communicate material findings as appropriate. This policy does not authorise access to another customer workspace, denial-of-service testing, social engineering, or destructive testing.