Flixil Security & Vault Architecture

Security built into
the core architecture.

We treat your API keys, model workflows, and telemetry metrics with the highest standard of cryptographic isolation and privacy safeguards.

Hardware AES-256-GCM Envelope Encryption

Provider secrets are encrypted using AES-256 in Galois/Counter Mode (GCM) with random 96-bit cryptographic nonces per record, preventing plaintext recovery.

PostgreSQL FORCE ROW LEVEL SECURITY (RLS)

Multi-tenant workspace isolation is strictly enforced at the SQL kernel level. Cross-tenant queries are cryptographically blocked by current_user_id() context.

Zero Prompt & Completion Retention

Flixil is architected with zero-retention data planes. Prompt contents and model outputs pass through ephemeral memory buffers and are never stored or logged.

Virtual Key Isolation & Spend Envelopes

Generate sandboxed Flix Keys for specific apps, repos, or developer environments with strict spend caps, model restrictions, and instant remote revocation.

Distributed Rate Limiting & DoS Protection

Atomic Redis sliding-window algorithms throttle excessive request volume, preventing runaway autonomous agent loops and credential brute-force attacks.

Automated Adversarial Security Testing

Every build executes 16+ adversarial security test suites verifying protection against IDOR, BOLA, JWT tampering, mass-assignment, SQL injection, and SSRF.

How Flixil Key Vault Decryption Works

When an application issues a completion request through the Flixil gateway, the following cryptographic pipeline executes:

  1. The virtual Flix Key is authenticated and checked against tenant budget limit and allowed model list.
  2. The encrypted master key ciphertext is fetched from PostgreSQL using Row-Level Security isolation.
  3. The master key is decrypted in volatile memory buffer using AES-256-GCM authenticated cipher.
  4. The completion request is proxied to the upstream provider (e.g. OpenAI) with TLS 1.3 encryption.
  5. The plaintext secret buffer is immediately zeroed in memory upon request completion.