Security
How the Solver-one platform is built to protect keys, money and data (the platform is not yet live). Report a vulnerability to security@solver-one.ai — we acknowledge within 2 business days and do not pursue good-faith researchers.
Key custody
- Your API keys are stored encrypted at rest (AES, authenticated) with a key held only on the server; only you (signed in) can reveal them. Operators see masked keys only.
- Operator (admin) access requires two-factor authentication (time-based one-time codes) in production, and every operator action that changes money, access or an account's state is written to an append-only action log: the application connects to its database with a least-privilege account that can add log entries but cannot change, delete or truncate them; entries are retained for 7 years.
- Our upstream provider credentials are never exposed to customers: the gateway strips and replaces every upstream error before it reaches you, including inside streamed responses.
- Passwords are hashed with bcrypt. A password reset signs out every session. Five failed logins lock the account for 15 minutes.
Content non-retention
Prompts and responses pass through to the model provider and are not written to our database or logs. We keep token counts, cost and timing only.
Money
Every change to your balance is a row in an append-only ledger and is applied exactly once even if a component fails mid-way; payments are credited only after Stripe confirms them as paid and the amount matches.
Transport and infrastructure
- TLS 1.2+ on every public endpoint; HTTP-only, SameSite session cookies.
- The platform is not yet live. When it launches, internal services will not be reachable from the internet and backups will be encrypted and access-restricted.
- Per-key rate limits and a hard cap on output tokens per request protect against runaway cost.
Data location and processors
At launch, the platform's processors will be Alibaba Cloud (model inference through Model Studio in the Singapore region, server hosting in Singapore and encrypted backups in Hong Kong), Stripe (payments), Cloudflare (content delivery and protection) and Lark (business email, stored in Japan); the platform's Privacy Policy will list them in full. This website's own processing is described in the website privacy notice.
Responsible disclosure
Email security@solver-one.ai with steps to reproduce. Once the platform is live, please do not access other customers' data or degrade the service while testing.