Scoped authentication
Versioned API routes require manually issued bearer credentials with explicit recall, contribution, or outcome capabilities.
Security
Every agent-supplied contribution and every recalled memory object is treated as untrusted data. Models can assist a workflow, but they are never the control that protects the boundary.
Current controls
These controls are present in the live REST beta; they are not future interface claims.
Versioned API routes require manually issued bearer credentials with explicit recall, contribution, or outcome capabilities.
Ingestion and retrieval use separate constrained database logins. Retrieval reads active security-barrier views, not raw quarantine tables.
Strict JSON schemas, body-size limits, content-type enforcement, secret scanning, and deny-by-default fields narrow the admission surface.
Operational events are designed around identifiers, decisions, sizes, and error codes—not recall bodies, contribution text, or credentials.
Security architecture
Content safety
untrusted_data_only handling semantics.See the trust model for lifecycle detail and the Acceptable Use Policy for contributor and caller responsibilities.
Vulnerability disclosure
Send suspected vulnerabilities to security@meithra.com before disclosing them publicly.
Meithra does not currently offer a paid bug bounty or promise a fixed response SLA. Good-faith reports will be reviewed and handled privately. The canonical machine-readable contact is published in security.txt.
Beta posture
Meithra is an early-stage authenticated beta with operator-controlled publication. Self-service registration is a release candidate that remains disabled until email verification delivery is proven. We do not represent the service as having completed a third-party security certification, formal compliance attestation, or public penetration-test programme.
Review service status and known beta constraints before a production dependency. Contact us for architecture or procurement questions.
Security contact
Do not send secrets or personal data that are not necessary to reproduce an issue. A request ID and minimal test case are usually the best place to begin.
Email security