Security
How Skryp protects accounts, keys and data. Each point describes how the service works today.
Updated 2 October 2026
Accounts and sessions
- Passwords are stored only as salted scrypt hashes and compared in constant time. Sign-in, sign-up and reset attempts are rate-limited.
- Signing in sets one cookie that page scripts cannot read, sent only over HTTPS and withheld from other sites’ forms and background requests. We store only a SHA-256 hash of its value. Every request that changes something must also carry a header that other sites cannot add.
- A password reset link works once, for one hour, and signs out every other session. Changing your password signs out your other sessions.
API keys
- Keys are shown once, when created, and stored only as SHA-256 hashes. You can rotate or revoke them at any time.
- A key can use its workspace’s tools and read its data, but cannot manage keys, passwords or billing; those need a signed-in person.
Saved logins
Cookies and site storage for saved logins are encrypted with AES-256-GCM, with a separate key for each login derived from a master key that is kept apart from the database. Each encrypted record is bound to its workspace and login, so it cannot be decrypted anywhere else. Saved logins are used only for their own workspace’s requests.
Your data
- Each workspace sees only its own requests, results, datasets, recipes, monitors, workflows and files; ownership is checked on every read.
- Requests to private, local and cloud-metadata network addresses are refused, at every redirect.
- Copies of results are kept for 14 days for the dashboard. Closing an account deletes its details and its workspace’s data. Backups are overwritten within 14 days.
Payments
You pay on Paystack’s own page, so card numbers never reach our servers. Every payment is confirmed with Paystack’s API before credits are added, and payment notifications are accepted only with a valid Paystack signature.
Report a vulnerability
Email support@skryp.dev with the details and steps to reproduce. Please do not access other people’s data, disrupt the service or run automated scans against it while testing. How we handle personal information is in the Privacy Policy.