Security
Updated July 30, 2026
This page is informational and describes how security works when you use the Site and the Product. The binding conditions are set out in the Terms of use and the Privacy policy.
Where your data lives
Your workspace, rules, memory, and files live on your computer and, if you connect Telegram, on your personal server.
The Product creates encrypted workspace backups in Kvelo infrastructure. No more than the seven latest copies are kept; older copies are removed automatically. The recovery key is derived from the access key recorded by the Provider. This gives the Provider a technical route to decrypt a copy for a recovery agreed with you. It is not zero-knowledge storage.
Access keys
The Model is connected separately. Its key or subscription is handled on your computer or personal server according to the connection method you choose.
For some services the Product uses the external authorization broker Composio, or another broker shown during setup. In that case, tokens and requests are handled by that provider under its terms. Kvelo does not ask for the password to the connected service, but data required for a task may pass through the Model, service, or broker. You approve each connection and can revoke it in the service or with the connection provider.
What the Provider can see
The Provider processes data entered in the Site form, account and access-delivery data, limited technical logs, and encrypted backups. Backup contents are not analysed in ordinary operation, but can technically be decrypted for an agreed recovery or a binding legal requirement.
The full list of data, purposes and retention periods is in the Privacy policy.
How the Site and backups are protected
- data is transmitted over HTTPS only;
- a strict content security policy is applied;
- embedding the Site in third-party frames is blocked;
- the form is protected by Cloudflare Turnstile and an origin check;
- Site hosting, DNS, and encrypted-backup storage are provided by Cloudflare;
- a backup is encrypted before upload, and no more than seven copies are retained;
- access to infrastructure and recovery operations is limited to those who need it for their role.
What is worth doing on your side
Do not rely on the Kvelo backup as the only copy of your working files. Check the Agent’s output before you use it, send it to anyone or make decisions on the strength of it. Grant access one service at a time, and revoke it in the service when it is no longer needed.
Reporting a vulnerability
If you find a vulnerability, send a description and steps to reproduce to info@kvelo.dev. We will acknowledge it and fix it.
Please do not disclose the details publicly until it has been resolved.