Security

Selra treats tool use and access as first-class controls — not afterthoughts.

Governed tool path

Structured ActionPlans are validated and checked by policy before the tool gateway runs anything. Allowlists, authz, and iteration limits apply.

Grounded failures

When a tool fails or is unavailable, Selra surfaces clear status. Respond paths are instructed not to invent sources or results.

Access before remote share

Prefer Cloudflare Access (or equivalent identity gate) before exposing remote environments. No custom password invention on the public marketing surface.

Least privilege integrations

Connectors are intended to be scoped (for example read-oriented Graph search when configured). Product credentials stay out of this static site.

This website

  • Static marketing pages on Cloudflare Pages.
  • No application secrets embedded in client assets.
  • Security headers via _headers (nosniff, frame denial, referrer policy).

Report an issue

Email [email protected] with “Security” in the subject. Please include enough detail to reproduce; do not include unrelated customer data.