Security built into
the core architecture.
We treat your API keys, model workflows, and telemetry metrics with the highest standard of cryptographic isolation and privacy safeguards.
Hardware AES-256-GCM Envelope Encryption
Provider secrets are encrypted using AES-256 in Galois/Counter Mode (GCM) with random 96-bit cryptographic nonces per record, preventing plaintext recovery.
PostgreSQL FORCE ROW LEVEL SECURITY (RLS)
Multi-tenant workspace isolation is strictly enforced at the SQL kernel level. Cross-tenant queries are cryptographically blocked by current_user_id() context.
Zero Prompt & Completion Retention
Flixil is architected with zero-retention data planes. Prompt contents and model outputs pass through ephemeral memory buffers and are never stored or logged.
Virtual Key Isolation & Spend Envelopes
Generate sandboxed Flix Keys for specific apps, repos, or developer environments with strict spend caps, model restrictions, and instant remote revocation.
Distributed Rate Limiting & DoS Protection
Atomic Redis sliding-window algorithms throttle excessive request volume, preventing runaway autonomous agent loops and credential brute-force attacks.
Automated Adversarial Security Testing
Every build executes 16+ adversarial security test suites verifying protection against IDOR, BOLA, JWT tampering, mass-assignment, SQL injection, and SSRF.
How Flixil Key Vault Decryption Works
When an application issues a completion request through the Flixil gateway, the following cryptographic pipeline executes:
- The virtual Flix Key is authenticated and checked against tenant budget limit and allowed model list.
- The encrypted master key ciphertext is fetched from PostgreSQL using Row-Level Security isolation.
- The master key is decrypted in volatile memory buffer using AES-256-GCM authenticated cipher.
- The completion request is proxied to the upstream provider (e.g. OpenAI) with TLS 1.3 encryption.
- The plaintext secret buffer is immediately zeroed in memory upon request completion.