Encrypted provider keys
Production OpenAI keys are encrypted before database storage.
Production OpenAI keys are encrypted before database storage.
Logs, caches, API keys, credits and settings are separated by company.
Provider keys used by the local tester remain on the customer’s own computer and are not uploaded to Varion.
Request metadata is logged; prompts and generated answers are not stored in normal request logs.
Public traffic is terminated through Caddy with automatic TLS.
Hashed Varion keys, team roles, rate limits, spending limits and optional IP allowlists.
Automatic database backups with owner-triggered backups available.
Unverified workflows remain passthrough instead of forcing compression.
Report security issues privately to security@varion.tech. Do not include live API keys in email.