# Security

> How Kurrens protects your data, and how to report a vulnerability.

- **Encryption in transit.** All traffic to the API, website, and docs uses TLS 1.2 or later.
- **No content at rest.** Prompts and completions are processed in memory and excluded from logs.
- **Hashed keys.** API keys are stored as salted hashes and shown only once at creation.
- **Least privilege.** Production access is role-based and requires multi-factor authentication.

## Reporting a vulnerability

Email [support@kurrens.ai](mailto:support@kurrens.ai?subject=Security%20report) with the subject line "Security report",
steps to reproduce, and any proof of concept. Please give us
reasonable time to fix the issue before disclosing it publicly.

Jailbreaks, prompts that produce harmful output, and model hallucinations are not security vulnerabilities — report model
misuse to [support@kurrens.ai](mailto:support@kurrens.ai?subject=Abuse%20report) with the subject line "Abuse report".

More at [kurrens.ai/security](/security).
