Security at PsiGuard.
PsiGuard is built to handle as little of your sensitive data as possible, and to protect what it does handle. Here's how — in plain terms, with no claims we can't back up.
How we protect your data.
Minimal exposure by design
The API returns only your answer and a coarse protection signal. PsiGuard's internal monitoring signals are produced and kept on our servers — they never cross the wire.
API keys are hashed
We show your key once, then store only a one-way SHA-256 fingerprint of it — never the key itself. You can revoke any key instantly, and rotate by issuing a new one.
Your provider keys, encrypted
If you bring your own AI provider key, it's encrypted at rest and used only to make model requests on your behalf.
Payments handled by Stripe
All card payments go through Stripe, a PCI-DSS-certified processor. PsiGuard never sees or stores your full card number.
Encrypted in transit
All traffic to and from PsiGuard runs over HTTPS, with TLS terminated through Cloudflare in front of our application.
API history isn't retained
Conversation history you pass to the API is used to generate that turn and is not retained by the API as conversation state.
Data & sub-processors.
PsiGuard runs on a small set of trusted providers, each handling only what it needs to. To generate a guarded answer, your prompt is sent to the AI model provider configured for your account. Full detail is in our Privacy Policy.
- RenderApplication hosting and storage.
- Firebase / FirestoreAuthentication and database (Google).
- StripePayment processing.
- ResendTransactional email.
- CloudflareDNS, content delivery, and network security.
- AI providersOpenAI, Anthropic, Google, DeepSeek, xAI — response generation.
Reporting a vulnerability.
If you believe you've found a security issue, we want to hear from you. Email [email protected] with the details and steps to reproduce. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We're grateful for responsible reports and will respond as quickly as we can.
Where we are today.
PsiGuard is a small team in active beta. We've built security into the product from the start — the practices above are real and in place today — but we don't yet hold formal certifications such as SOC 2 or ISO 27001. We'd rather tell you exactly what we do than imply more than we can stand behind. As the product matures, we'll expand both our practices and this page, and we're glad to talk through specifics with enterprise teams: [email protected].
See also: Privacy Policy · Terms of Service