Security
Draft · July 2026 · Webik, LLC
Draft — under legal review before the founding beta opens.
This page is a control summary, not a certification, audit opinion, warranty, or security SLA.
Current controls
- TLS for browser, API, and internal service connections in production.
- API keys are shown once at creation and stored only as hashes — a database read cannot recover a key.
- Envelope encryption for stored secrets, with decryption in service memory when needed.
- No prompt or response body storage by default; request logs are metadata only (see the privacy policy).
- Prepaid, fail-closed billing: pre-dispatch reservations, no negative balances, and no charge when the engine reports no usage.
- Append-only ledgers for money movement and operator actions, with audited mutations.
Important limits
No system is perfectly secure. Inference runs on GPU capacity from the compute providers on the subprocessors list, whose physical and platform controls are outside our direct operation. WebikAI does not currently claim SOC 2, ISO 27001, or other independent certification. Do not send regulated or highly sensitive data during the beta.
Report a vulnerability
Email [email protected] with a concise description, reproduction steps, impact, and safe contact details. Do not access other customers' data, disrupt service, or publish before coordinated resolution. We do not yet promise a bug bounty; good-faith reports are triaged and answered.