Security
Lyra is built so you stay in control of your account, your keys, and what gets published. This page explains the security features you rely on and the choices that keep you in control.
Account security
- Email verification. Every account verifies its email with a 6-digit code, even accounts created with Google or GitHub.
- One-time codes. Sensitive steps use one-time codes sent to your email.
- Password reset. Email and password accounts can reset a forgotten password with a reset link.
- Access gate. New accounts request access before the workspace opens, part of Lyra's controlled rollout.
- Rate limiting. Requests are rate limited to protect your account.
Your keys
Your Claude credential and optional Gemini key are validated before they are saved and stored encrypted. When you replace a credential, the previous one is invalidated immediately.
Because Lyra runs on your own key, you control the budget and can rotate the key on your provider account at any time. See Add your Claude key.
Repository access
Lyra connects to your repo through the Lyra GitHub App, not a personal access token. You choose which repositories the app can reach, and you can disconnect at any time. Lyra works only through standard GitHub objects: branches, pull requests, issues, and review comments. See Connect your repository.
Nothing publishes without you
The most important control is the merge. Lyra opens pull requests and tags you, but she never merges. Nothing auto-publishes. Every post reaches your blog only when you merge it.
Data isolation
Your data is isolated per tenant, so each account's websites, posts, and settings are kept separate from every other account's.
Payment security
All payment runs through Stripe's hosted checkout and customer portal. Card details never touch Lyra. See Billing.
What's next
- Add your Claude key: Manage and rotate your credential.
- Connect your repository: GitHub App access.
- Reviewing and merging: The merge is always yours.
- Billing: Payment through Stripe.