Public website information

Security information.

This page describes the limited, observable scope of the public Ox Alpha website. It is not a security certification, audit, service-level agreement, or incident-response commitment.

Scope: public website onlyLast reviewed: 2026-08-23

Scope of this security information.

The visible public website is a static information and documentation site. It does not show a first-party login, account-management interface, file-upload flow, website form, or website-hosted API-key entry flow.

This page does not make claims about encryption, access controls, logging, retention, vulnerability management, security monitoring, testing, backups, certifications, or incident response unless those controls are verified and approved for public disclosure.

Integration guidance

Keep API keys on the server.

For TokenRa integrations, keep API keys in a server-side environment variable or another appropriate secret-management mechanism. Do not embed a production key in browser JavaScript, a static page, a client-side bundle, or a public repository.

Use a trusted backend boundary for provider requests, validate model output before it can trigger an action, and avoid logging credentials or sensitive prompt content. The API documentation provides additional integration guidance.

Public pages are not a secure reporting channel. Do not send credentials, secrets, personal data, payment data, or detailed vulnerability information through public or unverified channels.
Provider boundary

TokenRa services are independently operated.

TokenRa controls its own API infrastructure, authentication, service availability, account management, billing, support, and data-processing practices. Those services are outside the scope of this public website and should be verified directly with TokenRa.

When designing an application, set timeouts and budgets, handle provider errors safely, limit tool permissions, and require suitable review before high-impact actions. These are development practices, not a representation of TokenRa’s security controls.

Reporting status

A verified website reporting channel is not published.

This site does not currently publish a verified vulnerability-reporting channel, security mailbox, PGP key, Safe Harbor statement, response timeline, or remediation commitment. Do not assume that a report sent to an unverified address will be received or handled securely.

For a TokenRa API or account issue, use TokenRa’s official security or support channels. A dedicated reporting process for this public website can be added when a verified operating contact and handling process are available.