Security

Effective: 2026-10-01

Agents write, people stay in control

A snapshot before every agent edit

  1. ①

    Before an agent changes a document through MCP, VikiEditor saves a version of the document as it was. Version history shows what changed, and any version can be restored — so an agent's edit is never the only copy.

  2. ②

    Every MCP write is recorded with the session that made it: the agent (for example Claude Code), the name the session gave itself, when, and which sections it touched. The home feed and the document's history show this trail.

Only people close feedback

  1. ①

    Feedback threads are written by people. An agent session can take a thread, change the document and reply with what it did, but it cannot close the thread: the person who left it checks the result and closes it.

  2. ②

    Handoffs work the same way: an agent leaves what is left for the next session; a person can see, edit or discard them at any time.

Shared and public documents are untrusted input

  1. ①

    Documents opened through a share link and published blog posts can be read by anyone with the link, and collaborative documents can be edited by the people you invited. Text in them may have been written by someone other than you.

  2. ②

    Treat that text as data, not instructions: an agent reading a shared or public document should not follow directions found inside it. VikiEditor's own agent tools only act on the explicit calls your agent makes, never on document contents.

Access and credentials

How agents authenticate

  1. ①

    MCP clients connect with OAuth 2.1 (authorization code with PKCE, dynamic client registration, tokens bound to the VikiEditor MCP resource) or with an API key you create in Settings → Connections.

  2. ②

    API keys are stored only as a SHA-256 hash; the plain key is shown once, when you create it. Keys can be renamed, disabled and deleted at any time, and each key's last use is visible.

  3. ③

    Every MCP request carries a credential; there is no anonymous access to your documents through MCP.

Sign-in sessions

  1. ①

    Browser sessions use httpOnly cookies; tokens are not exposed to page scripts. Refresh tokens rotate on use, and a reused refresh token invalidates the session it belonged to.

  2. ②

    Requests that change data are checked against the site's own origin.

Where data lives

Storage and transport

  1. ①

    Documents and versions are stored in PostgreSQL on infrastructure the operator runs; uploaded images are stored in Cloudflare R2 and served from img.piai.company. All traffic to the site and the API is encrypted in transit (TLS).

  2. ②

    A database dump is taken before every deploy of the backend, so a faulty release can be rolled back with its data.

Reporting a security issue

  1. If you find a vulnerability, write to support@piai.company. Please include the steps to reproduce it and do not access other people's data while demonstrating it. We reply to every report.

This page describes the service as of the effective date and is updated when the product changes.

Business information

Company
to be registered
Representative
to be registered
Business registration no.
to be registered
Mail-order business no.
to be registered
Address
to be registered
Email
to be registered
Phone
to be registered