Security
Controls
Vault-encrypted keys
Provider keys are envelope-encrypted per org and only decrypted inside the call path. They never reach an agent's machine.
Scoped keys and tokens
API keys and agent tokens are limited by capability, provider, spend cap and expiry.
Audit log
Every call records who, which token, which provider, what it cost and the result status.
No payload retention by default
Request and response bodies are dropped after delivery unless you turn on retention for debugging.
Key custody
Each org's provider keys are encrypted with a per-org data key, itself wrapped by a key held in a managed KMS. Keys are decrypted only in the worker that makes the provider call and are never returned by any API.
Tokens
API keys and agent tokens are hashed at rest, shown once, scoped to capabilities and providers, capped by spend and optionally set to expire.
Reporting a vulnerability
Email security@gridrouter.io. We acknowledge reports within two business days.