Active today
Core safeguards
- Firebase authentication for account identity.
- EU-region Cloudflare storage for configured user files.
- Server-side usage, budget and protected-state checks.
- Provider keys stay encrypted and server-side.
Security
Tavory separates account identity, protected server checks, provider access and visible costs. This overview distinguishes what is active from what depends on setup.
Browser
Authenticated request
Tavory server
Rights, keys and budget checks
AI provider
Only the selected request path
Answer
Usage and result return
Provider keys are handled server-side. The browser never receives a provider secret.
Status by layer
Active today
Setup required
Planned / not claimed
Identity is checked before protected account actions.
Keys are never returned to browser code.
Usage is connected to plan limits and visible costs.
Configured user files are stored in Cloudflare’s European region.