Credentials
API keys and Mailgun credentials should stay server-side and out of public repositories.
SECURITY
A deliberately precise public security page for an infrastructure product that should never bluff about controls or certifications.

TRUST WITHOUT OVERCLAIMS
This public page is deliberately conservative until Galxy publishes its formal security architecture, certifications and control set.
API keys and Mailgun credentials should stay server-side and out of public repositories.
Deploy the public site behind HTTPS and redirect plain HTTP at the edge.
Use the current product documentation for supported authentication and authorization controls.
Route security questionnaires and contractual requirements to the enterprise sales process.
Do not add claims such as SOC 2, ISO 27001, DRM support, encryption-at-rest guarantees or specific retention policies until Galxy can substantiate them.
START SMALL. SCALE CLEANLY.
Enterprise requirements are handled directly through sales so the answer can match the current platform and contract.