Security at Elektric
Clear boundaries for your AI infrastructure.
Elektric is pre-beta. This page describes protections that exist today, the data required to operate the service, and the limitations we are still working through.
Last updated August 12, 2026
API keys
Project API key secrets are shown once when created. Elektric then stores a non-reversible hash and a short prefix, not the raw secret. Keys can be disabled or permanently revoked from the dashboard.
Keep API keys in a trusted server or edge environment. Never place them in browser JavaScript, public mobile applications, source control, or logs.
Authentication and sessions
Dashboard access uses browser authentication through OAuth or email magic links. These user sessions are separate from machine-to-machine project API keys, so a project key cannot sign in to the dashboard.
Provider credentials
Credentials for supported AI providers remain behind Elektric’s server-side infrastructure. They are not returned through the customer API or exposed to customer applications.
Data handling
Elektric does not retain prompt or response content by default. Requests are processed by third-party AI providers to produce a response, and those providers may apply their own data-handling terms.
Elektric retains operational metadata needed to run and account for the service, including request timing, token counts, latency, status, routing and model information, billing records, and project or API-key identifiers. This statement describes Elektric’s retention, not a provider’s independent practices.
Infrastructure
Elektric runs on Cloudflare infrastructure, including Workers and D1. Access controls, rate limits, concurrency controls, request-size limits, and spend controls help protect the service and customer projects.
Billing security
Card entry and payment collection use Stripe-hosted Checkout. Elektric does not store full payment-card details. Elektric does retain the payment status, amount, provider reference, and related accounting records required to maintain prepaid service credits.
Report a security issue
Elektric is establishing a dedicated security reporting channel before public beta. Until that contact is published, do not send sensitive vulnerability details through public channels.
Current limitations
Elektric is a pre-beta service. It has not completed a formal third-party security audit and does not currently claim security certifications or compliance attestations. Security practices and this page will evolve as the service approaches broader availability.