Security

Your key stays yours.
It never leaves the server.

Relay is built so a credential never reaches the browser, an agent only answers from permitted context, and a human is reached on the exception with the full thread.

  • Keys stay server side

    Your Aicoo key is validated on connect and stored on the server only. It is never sent to the browser, never bundled into client JavaScript, and never written to a log. Calls to a teammate's agent are signed on the server with their key, not yours.

  • httpOnly cookie identity

    You are identified by an httpOnly session cookie set when you connect. Page scripts cannot read it, which keeps your identity out of reach of anything running in the browser. There is no token sitting in local storage for a script to lift.

  • Permissioned context, per person

    An agent only answers from the context its owner allowed it to see. There is no shared corpus pooling everyone's documents. When you relay a question you reach one person's agent and exactly the material they chose to make answerable, nothing wider.

  • The escalation guarantee

    When a topic is genuinely new or sensitive, the agent stops rather than guesses. Relay marks the request escalated and notifies the human through Aicoo's send_message_to_human, with the full thread attached. A person is pulled in on the exception, with full context.

  • Encrypted in transit

    Every request between your browser, Relay, and Aicoo travels over HTTPS. Nothing about a relay or its answer crosses the network in the clear.

  • No keys in responses or logs

    By contract, no Aicoo key ever appears in an API response, and no key is written to a log line. The browser sees members as names, roles, and an online dot. It never sees a credential.

Aicoo OAuth is not released yet, so Relay uses the sanctioned API-key model where each person's own key acts on their behalf. We will adopt OAuth when Aicoo ships it.