KlecherAI is engineered with strict context isolation and defense-in-depth security principles.
Every tenant context is enforced at the database query layer. Two contexts owned by the same user never cross-leak memories, preferences, or document metadata.
Session tokens are validated server-side with session-version revocation mechanisms, HMAC rate limiting, and password hashing using bcrypt.
If you discover a security concern, please report it to security@klecherai.in.