Security

How we protect your account

A plain-English rundown of how your API key is handled, how spend is limited, and how customer data is kept separate. If anything here is unclear, ask us directly.

Top-down view of the SpyderByte robotic spider mascot with glowing circuitry

How your API key is stored and protected

When you connect your OpenAI or Anthropic account during setup, your API key is encrypted at rest. It is never written to logs and never included in any export or generated document. You can remove your key from your account at any time, which stops any further use of it by the platform.

If you connect a supported provider subscription instead of an API key, sign-in happens through your provider's own flow — SpyderByte never sees your provider password. The access credential your provider issues is handled the same way as an API key: encrypted at rest, never logged, never exported, and removable at any time.

Spend caps

Every workflow run is bounded by a per-run spend cap and a daily spend cap, both on by default. Caps limit the work the platform will start or continue on your behalf, based on usage information your provider makes available — they are a platform-side safeguard, not a control on your provider account, and they do not limit what your provider bills you. You can adjust either cap at any time in your account settings, and you remain responsible for monitoring your own provider account.

Separately, your provider enforces its own rate limits, usage allowances, and reset windows (hourly, five-hour, weekly, and similar). If your provider limits or resets your access mid-run, a workflow can pause or stop before it completes — that is between you and your provider and outside SpyderByte's control. You can start the run again once your access is restored.

Data isolation between customers

Each customer account is kept isolated from other accounts. Your API key, your generated files, and your workflow history are scoped to your account and are not accessible from other customers' accounts.

Account security basics

Each SpyderByte account is a single-user license with one login. Use a unique, strong password for your account, and treat your login credentials the same way you would for any service holding business documents and a connected API key.

What SpyderByte cannot see

SpyderByte does not resell AI compute and does not have access to your provider billing. Because you connect and pay your own OpenAI or Anthropic account directly, we cannot see your provider invoice or usage charges — that relationship stays between you and your provider.

How to report a concern

If you notice anything unexpected in your account, or want to report a security concern, email support@spyderbyte.cloud or reach us through our contact page. We respond to security reports directly.