Security model

Keys, session tokens, host JWTs, secret storage, tool guard rails and what the model provider sees.

Credentials

CredentialWho holds itLifetimeNotes
Publishable key kl_pub_…The appUntil revokedOpens sessions. Safe to ship; it cannot read data or change configuration. Stored hashed (SHA-256) server side.
Secret key kl_sec_…Your serversUntil revokedNotifications, management. Never in client code. Stored hashed.
Session token kst_…The app, in memoryShort; refreshed by the SDKEd25519-signed by the runtime. Revocation is checked on every request.
Host JWTIssued by your backend, passed to the SDKWhatever you setVerified with the HS256 secret or the JWKS URL you configure.
Dashboard sessionBrowser cookie30 daysEmail one-time code (10-minute validity, 5 attempts), HMAC-signed cookie, address allowlist plus workspace membership.

Secrets vault

Model keys, tool credentials and push service accounts are project secrets. They are encrypted with envelope encryption: a per-organisation data key encrypts each value with AES-GCM and additional authenticated data bound to the organisation and secret id; the data key is wrapped by a key-encryption key that exists only as a Worker secret. Dashboard members see names and last-used times, never values. Agents and tools reference secrets by name.

Tool guard rails

  • Arguments are validated against the tool’s JSON schema before any request is made.
  • The SSRF guard allows http and https only, refuses credentials in URLs and private, loopback, link-local and metadata hosts, and does not follow redirects at all.
  • Every call has a timeout and is logged with status and latency.
  • Act as user forwards the verified end-user identity, so your API decides permissions.
  • Require confirmation pauses the turn until the user approves in the chat.
  • The model can only render component types on the agent’s allowlist and can only open URLs on the URL allowlist.

Isolation

  • Each conversation is its own Durable Object with its own SQLite log. No cross-conversation reads.
  • Sessions carry organisation, project, environment, end user and agent. Every /v1 request is scoped by them.
  • Rate limits: 30 user messages per minute per end user by default, enforced in the project’s tenant object.

What the model provider receives

The rendered system prompt, the last N messages, tool specifications, tool results and the current user message. Kletso does not train on your data and does not share it between customers. Use sensitive context keys to keep values out of prompts.

Jev (beta). For judgments Kletso also sends the user’s latest message, the previous assistant text and a compact copy of the UI last shown to TypeSafe’s API, on Kletso’s own key. TypeSafe does not train on requests. Sensitive context keys are never included. Per-agent switch: Behaviour → Jev turn judgments.

Dashboard access

Sign-in is by email code to an allowlisted address that also has a workspace membership. Roles are owner, admin, developer and viewer. Developers and above edit agents, tools, workflows, triggers and components, and add or rotate secrets (never read them). Owners and admins manage API keys, webhooks, settings and members. Only owners change roles. Viewers read everything. A membership can be scoped to specific projects, so an outside collaborator sees only their project. Invite members from Settings → Organization.

Reporting

Security issues: security@kletso.ai. Please include reproduction steps; we acknowledge within two business days.

Last updated 2026-09-28 · Report an issue with this page