Read-only reporting scope
Every connector signs in with a reporting or billing key and calls usage and cost endpoints only. Pharos never writes, never runs a model, and never touches your account settings. Revoke the key at the provider and Pharos loses access at once, without asking us.
Prompts and completions are never read
The endpoints below return totals: tokens, requests, line items, and amounts, grouped by model, project, key, or member. None of them return message content, and Pharos calls no endpoint that does.
Your workspace is separated in the database
PostgreSQL row-level security keeps each workspace apart. Every table carries a policy that ties a row to one workspace, so the database enforces it rather than the app. A test suite runs those policies against a live database.
Credentials encrypted before storage
Provider keys and webhook secrets are encrypted with AES-256-GCM before they reach the database, each with its own key. You can also keep them in a dedicated secrets store instead of the application database.
No language model computes a figure you are shown
Code computes every number you see, from stored provider records, in whole micro-dollars. The agent explains the evidence and drafts what to do next. When Pharos sends an agent request to a model provider, it asks for zero data retention.
Sign-in controls
You verify your email before a workspace is created. Sign-in, sign-up, and recovery are rate limited per account and per address, in fifteen-minute windows. Sessions live in signed, HTTP-only cookies.