Security & trust

Your keys. Your code. Your data.

We’re a small team being direct about what matters most: here is exactly what we do, and don’t do, with your code and your conversations.

Protected companion communication

Vyohm uses authenticated, encrypted transport for activation, approvals, diffs, and questions between your devices and the companion service.

Bring your own key

Use your own API key and your requests go straight from your machine to your chosen model provider. Your code never has to pass through a Shaktii server, while plan features still govern workflow capacity, approvals, visibility, and support.

Device-bound licenses

Activation ties your license to a specific device fingerprint. If a device is lost or compromised, contact us to revoke or rotate its access.

BYOK data flow

How your code moves when you bring your own key

With BYOK, Shaktii’s servers are never in the path between your source code and the model.

Your machineVS Code + Shakti
Model providerUsing your API key

Activation and companion approval flows route through Vyohm using authenticated, encrypted transport — your BYOK source-code traffic does not.

Data boundaries

The honest list

  • Your source code at restCode is processed in memory for the run in progress and is not retained on our servers afterward.
  • Your API keys in plaintextKeys are encrypted at rest and only decrypted at the point of use, on your device where possible.
  • Unnecessary message contentWe keep companion-message handling limited to delivery and service operation. Do not use chat to share secrets that your organisation cannot authorise the service to process.

We’re early — if you find a gap between this page and reality, tell us. It’s the fastest way to make both better. The full detail lives in our Privacy Policy.

Questions about our security model

Reach the team directly — we answer security questions personally, before you sign up if you’d like.