Skip to content

Security: RouteKey/routekey

Security

SECURITY.md

Security Policy

Route Key API keys, account credentials, prompts, and usage records are sensitive. Do not publish them in issues, pull requests, discussions, screenshots, logs, or example files.

Reporting a vulnerability

Do not open a public issue for a suspected security vulnerability. Contact Route Key through the private support channel on https://routekey.ai/ and include:

  • A short description of the impact
  • The affected URL, endpoint, or example
  • Reproduction steps that do not include secrets or customer data
  • A minimal proof of concept when safe to share
  • A suggested mitigation, if available

If an API key or token is exposed, revoke it first, create a replacement, and then report the incident with the smallest necessary amount of information.

Safe disclosure

Please allow time for the team to investigate and deploy a fix before publishing details. Do not test against accounts, data, or traffic that you do not own.

There aren't any published security advisories