Security and privacy
Protect the Discord account that owns your data, keep machines trusted, verify downloads, and report issues.
On this page
Secure your Discord account
Your Discord login is the key to your Kovex data. Hardening it is the single highest value security step you can take.
- Enable two-factor authentication on Discord.
- Use a password that is unique to Discord.
- Review the applications and devices authorised on that account periodically.
Trusted machines
A connected machine can launch your accounts and receive the credentials needed to do it. Only link computers you control.
Credential handling
Kovex is built so that sensitive values are unreadable at rest and only leave the server when a job you asked for needs them.
- Passwords, authenticator secrets, and proxy credentials are encrypted before storage.
- Secret fields stay masked in the interface until you reveal them.
- Credentials are released for agent jobs on your own machines, and for reveal or export requests you make yourself while signed in.
Review connected machines
- Read the listCheck the names and last seen times against machines you actually use.
- Revoke anything unfamiliarRemove the entry, then change your Discord password if you cannot explain it.
Verify downloads
Every agent download is published with a SHA-256 value. Comparing it proves you installed the file Kovex published.
Privacy and disclosure
Public pages describe what is collected and how to reach the right team.
- The privacy policy explains what data Kovex holds and why.
- The security page explains how to report a vulnerability responsibly.
- Privacy and legal requests go to the address published on those pages.
Related guides
Still blocked?
Send us the guide you were following and what you saw instead. You get a private case link to track the answer.
