Security
How we keep shared machines trustworthy.
Use AI models on your own machines or machines shared with you. Here's how Saylek controls access, handles requests, and responds to security reports.
Who can use your machines
You choose who can use the models on your machines. Accepting someone's invitation does not share your machines back. You can stop sharing at any time.
Who can see your requests
The machine running the model needs to process your request to generate a response. Its operator can therefore access the request's contents. Requests also pass through Saylek, so use machines operated by people you trust. See our Privacy Notice for information about data handling and retention.
Sign-in
Sign-in is passwordless: a one-time magic link sent to your email, so there is no reusable password to phish, guess, or leak.
Report a security issue
Email security@saylek.com with a description and steps to reproduce it. Please report vulnerabilities privately and use this address rather than the support form.
What you may test
- saylek.com, its subdomains, and Saylek's services.
- The Saylek app and CLI, and how their updates are delivered.
What not to test
- Other people's machines. They are not ours to authorise testing against.
- Model output. Wrong or offensive output is not a vulnerability.
- That the machine running a request can read it. That is how the system works.
- Denial of service, spam, and social engineering of members or staff.
Disclosure policy
If you research in good faith, stay inside the scope above, and give us a chance to fix what you find before you publish it, we will not pursue or support legal action against you for it, and we will treat your report as authorised access. In return, do not access, alter, or keep data that is not yours, do not degrade the service for others, and stop once you have proved the issue.
What to expect
We will acknowledge your report, tell you what we think it is, and keep you updated while we fix it. We have not set a formal response time. If you would like credit when the fix ships, tell us and we will name you. For anything that is not a security report, use Contact.
This page describes the system as it runs in the public beta. No outside party has audited it, and nothing here is a certification. Where a claim is not yet true, this page says so rather than rounding it up.