Security
Use XYVA safely
Keep API keys, access tokens, pairing codes, production data, customer data, and confidential workflow content out of URLs, chat, email, screenshots, source control, and public issues. Use only approved product or agent settings for credentials.
For local providers, use a local service on your device. For cloud providers, configure credentials only through the approved agent or product settings. Do not share connection details or attempt to bypass product readiness checks.
Report a vulnerability
Use XYVA's private security contact or the approved responsible-disclosure channel. Include the minimum information needed to reproduce the issue, and do not publish exploit details, secrets, logs, personal data, or customer information.
General product feedback belongs in Community, not in a public security report.
