Trust
Security at Glytos
Your agents handle real conversations, so the platform underneath them has to be dependable. Here is how we protect your account and your end users conversations.
Encryption everywhere
Strong authentication
Tenant isolation
Recording is off by default
Your keys, protected
Abuse resistance
Data protection
Traffic to Glytos is encrypted with TLS. Sensitive secrets, such as the provider API keys you store, are encrypted at rest. Call recording is off by default and enabled only per agent, and a recording is served through us rather than a public storage link.
Access and isolation
Authentication is required on every state-changing request. Authorization is scoped to your organization, and each query is filtered by tenant so one customer can never read another customer data. Recording playback uses short-lived, unguessable links rather than public URLs.
Application security
The platform avoids the common high-impact classes: no dynamic code execution, parameterized database access only, output handling that prevents template injection, and an outbound request guard that blocks attempts to reach internal or private network addresses. A strict cross-origin policy is enforced in production.
Privacy controls
Recording is off unless you turn it on for an agent, and deleting an agent, a session or an organization removes its data. For Turkey KVKK and GDPR requests, including access and export, contact us and we will handle them. We do not claim certification against any healthcare or payment standard.
Operational practices
Production runs with hardened configuration validated at startup, least-privilege access for our team, and audit logging of administrative actions. We keep dependencies current and review changes before they ship.
Responsible disclosure
If you believe you have found a security issue, please tell us before disclosing it publicly. We investigate every report, act in good faith, and will not pursue researchers who follow responsible disclosure.