Skip to content
  • Everything in KeplarEvery feature and whether it is liveLive demoAsk a question now, no sign-upCreateDescribe or speak a site or appCreate showcaseDemos that set the barKeplar-OneThe engine behind every answerTeamsShared workspaces, roles and approvals
  • DocsHow everything worksAPI and widgetKeys, endpoints, embed scriptCommunity gallerySites people chose to shareChangelogWhat shipped, whenRoadmapWhat is next, what is not doneSecurityHow your data is protected
  • Pricing
  • Download
Sign InTry Keplar→
  • Product
  • Live demo
  • Create
  • Create showcase
  • Keplar-One
  • Teams
  • Resources
  • API and widget
  • Community gallery
  • Changelog
  • Roadmap
  • Security
  • Pricing
  • Download
Sign InTry Keplar→

One question. Multiple intelligences. One answer.

team@keplar.one

Product

  • Everything in Keplar
  • Overview
  • Live demo
  • How it works
  • Create
  • Create showcase
  • Community gallery
  • Keplar-One
  • Pricing
  • Download

Use Keplar

  • For you
  • For business
  • Agents
  • API and widget
  • Referral program
  • Create an account

Learn

  • AI answer engine
  • Compare AI models
  • AI study tool
  • AI slideshow maker
  • What is superintelligence?
  • Multi-model AI
  • Models we use
  • Guides
  • Docs
  • Blog
  • Changelog
  • Roadmap
  • Glossary
  • Prompt library

Company

  • About
  • Inquire
  • Help
  • Contact
  • Status

Legal

  • Privacy
  • Terms
  • Security

© 2026 Keplar One.

Theme
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do
Docs menu
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do

Docs/Privacy and security

Connected app security

How Keplar defends against server-side request forgery, prompt injection through tool output, secret leaks and silent tool changes when you connect MCP servers.

Updated October 3, 20261 min read

On this page
  1. Honest limits
  2. Reporting

Letting an AI call outside tools is powerful and risky. These are the controls and what they are for.

RiskWhat Keplar does
Server-side request forgery: pointing Keplar at your private network or a cloud metadata addressHTTPS only; hostnames must resolve to public addresses; private, loopback, link-local, shared, multicast and reserved ranges refused; connection pinned to the checked address; manual redirects (max three) re-checked on every hop
Credentials leaking into logsNo secrets in the URL; credentials encrypted at rest, bound to workspace and record; never returned to the browser
A tool silently changing meaningSchema hash; changed tools are disabled until re-enabled
Prompt injection through tool outputOutput stripped of invisible characters, instruction-like lines, active content and secret-shaped strings, then fenced and capped. Permissions are decided before the call from stored settings, so output cannot change them
Runaway usePer-plan, per-day, per-minute and concurrency limits; a credit charge per call; agent budgets
Unreviewed side effectsWrites, unknown tools and scheduled runs always wait for approval
ReplaysReceipts make an approval run once

Honest limits

These controls reduce risk; they do not remove it. Content from a tool is still read by a model, and a model can be misled by cleverly written text. A server you connect is trusted with the arguments you let it receive. Connect servers you trust, enable few tools, keep write tools on approval, and read what you approve.

Reporting

If you find a way around any of this, see Report a vulnerability.

Related

  • Connected apps (MCP) overview: Connect remote Model Context Protocol servers so Keplar and its agents can use outside tools, with per-tool permissions, approvals and plan limits.
  • Tool permissions and approvals: Read versus write tools, grants, auto-run rules, approval cards, schema-change locks and how scheduled runs always ask first.
  • Connect with OAuth (Beta): How OAuth sign-in for remote MCP servers works in Keplar, what it stores, what it refuses, and why it is labeled Beta.
PreviousAccount securityNextPublished sites and safety

Questions this page does not answer? Write to team@keplar.one, or try Keplar on your own question.

Try Keplar freeOpen Keplar→

On this page

  1. Honest limits
  2. Reporting