Skip to main content

Security, privacy, and telemetry

Never collect by default

DreamLayer does not send prompts, uploaded or generated images, local file paths, workflow JSON, provider keys, DreamLayer keys, authorization headers, private routing plans, model-selection reasoning, or forbidden provider and internal-cost metadata to monitoring.

Allowed operational telemetry

  • Environment and release identifier
  • Sanitized endpoint and error category
  • Public job and restricted correlation IDs
  • Duration, status, retry, and recovery state
  • Credit reserved, settled, or restored state without payment secrets

Local keys

Provider credentials stay in the loopback server process. Browser code receives neither the key nor its configuration value.

Managed boundary

Managed responses and logs must not reveal provider, model, workflow, route score, fallback policy, internal cost, or hidden reasoning. Report suspected cross-account access, double charge, data loss, secret exposure, or private-routing leakage immediately and stop affected execution.