Security
How JouleCloud protects API keys, traffic, and organization data during private preview.
Transport
All traffic is encrypted in transit with TLS — browser to this app, and this app’s server-side calls to the gateway. The API gateway itself is served over HTTPS at api.jouledns.com.
Keys and secrets
API keys belong to one organization and are created on the server. You can rotate yours in the console at any time. Status checks and playground requests also run on the server, so gateway keys stay out of the browser. Clerk manages sign-in and password storage.
Organization isolation and spending controls
Each API key, budget, rate limit, and usage record belongs to one organization. Organization budgets and requests-per-minute limits reduce the spending and traffic available to a compromised key until it is rotated.
Compliance status
JouleCloud currently supports general-purpose workloads. SOC 2 Type I/II is planned after private preview. Protected health information and cardholder data remain outside the supported scope. See the Acceptable Use Policy.
Reporting a vulnerability
Email hello@jouledns.com with subject “Security”. Our team reviews every security report.