Security
How Gulpy protects your accounts, and how to report a security problem.
How Gulpy protects your accounts
- An agent gets tools, not tokens. The sign-in token of a tool does not leave Gulpy.
- Each token is encrypted. Gulpy uses AES-256-GCM. Each encrypted value is tied to its record.
- You sign in at the provider. Gulpy does not see or keep the password of a tool.
- You approve each agent. You select the tools, and Read only or Read and write.
- You see each call. The list shows the agent, the tool and the time. It does not keep the content.
- You can stop access immediately. Remove an agent or a tool on the page My tools.
- Agents use standard sign-in. OAuth 2.1 with PKCE. Access tokens stop working after 1 hour.
Report a security problem
Send a message to [email protected]. We read each report.
- Tell us the steps that show the problem.
- Use your own account and your own data for tests.
- Do not read, change or delete the data of other people.
- Do not do tests that stop the service for other people.
- Give us time to correct the problem before you tell other people.
The machine-readable form of this section is at /.well-known/security.txt.