Security and access

Controls implemented in the Chatsax gateway, and the boundaries you should understand.

Provider key isolation

The Jina provider key stays in the server environment. Clients authenticate with a separate Chatsax key. Requests are routed to known provider endpoints; this is not an unrestricted HTTP proxy.

Scoped access

Generated keys are stored as hashes and listed with prefixes. The gateway checks scopes, per-key request limits, and ownership of classifier and batch resources. Administrator endpoints require administrator access.

Application boundaries

The gateway limits request size and upstream destinations. Reading a public page still exposes your submitted URL and extraction options to the provider. This page does not claim an independent security audit, certification, or that all provider risks have been eliminated.

Report a concern

Report security concerns privately to the workspace owner through the channel used to grant your access. Public GitHub issues are suitable for non-sensitive bugs only. Revoke a potentially exposed key before continuing work.

These statements describe Chatsax, not the policies of Jina or Cloudflare. Jina · Cloudflare