Security
This page describes DEKREL's confirmed account and project safeguards and the precautions users should take. It does not guarantee complete security or promise unverified certifications or monitoring systems.
1. Sign-In and Email Verification
You must sign in to create or open a project. An account with an unverified email address cannot access project pages.
Do not share sign-in links, verification codes, or one-time codes. If you receive a sign-in or verification message you did not request, do not open its links. Review the sign-in method first.
2. Project Access
A project detail page appears only when the signed-in account owns the project or has access under the project's organization permissions. Entering a project URL without that access does not reveal its content.
Final designs and plans, approval records, and generated organizational structures use the same project-access boundary. Before sharing project materials, confirm that you have authority to provide them.
3. External Actions and Important Changes
Approving a final design and plan and generating an organizational structure from it finalize results inside DEKREL. Those actions alone do not change an external account, initiate payment, change DNS, or deploy to production.
When DEKREL offers a feature that changes an external system, it separately shows the target and impact and does not execute it until the user explicitly confirms.
4. Information You Must Not Enter
DEKREL may detect and interrupt some obvious API keys, access tokens, password indicators, session tokens, or private-key formats. This does not guarantee detection of every secret.
Do not put the following in project conversations, files, or support inquiries:
- Passwords, sign-in verification codes, or one-time codes
- API keys, secret keys, access tokens, or session tokens
- Full card numbers, card PINs, or card security codes
- Resident registration numbers, passport numbers, or sensitive information not needed for the task
- Another person's personal information, trade secrets, or material you may not use
Describe the type of setting and where its value belongs instead of entering the secret itself. If a secret has been entered, revoke or change it through its issuer and obtain a new value.
5. AI Providers and Customer-Facing Information
DEKREL may send the project inputs needed for requested results to connected external AI providers. The providers actually used, information sent, processing locations, and retention rules are described in the Privacy Policy.
Customer screens show results that users need to review, including final designs and plans and organizational structures. Internal review processes, model-routing paths, authentication information, secrets, and internal execution logs are not included in customer-facing results.
6. Suspected Account Takeover
If you see a sign-in or project change you did not perform:
- For an external sign-in method such as Google, change its password and review active sessions.
- If the email account may be compromised, review that account's password and sessions.
- For DEKREL password sign-in, notify Support.
- Revoke and replace any exposed API key or access token through its issuer.
- Report the time, suspicious activity, and affected project to Support.
Also notify the card issuer or payment provider immediately if payment fraud is suspected.
7. Security Reporting
See Support's security-reporting guidance for the information to include and the precautions to follow. Do not continue accessing another person's account or data and do not alter data. Stop after the minimum activity needed to identify the issue.
8. Scope and Limitations
No internet service eliminates every risk. DEKREL's input detection is a supplementary measure for some obvious secrets. It does not replace your responsibility to confirm that entered or shared material is lawful and authorized.
This page describes current safeguards and their limits. It does not guarantee unverified certifications, a particular encryption level, round-the-clock monitoring, a dedicated incident-response organization, or identical protection across every external AI provider.