Skip to content

Security

Lyra is built so you stay in control of your account, your keys, and what gets published. This page explains the security features you rely on and the choices that keep you in control.

Account security

  • Email verification. Every account verifies its email with a 6-digit code, even accounts created with Google or GitHub.
  • One-time codes. Sensitive steps use one-time codes sent to your email.
  • Password reset. Email and password accounts can reset a forgotten password with a reset link.
  • Access gate. New accounts request access before the workspace opens, part of Lyra's controlled rollout.
  • Rate limiting. Requests are rate limited to protect your account.

Your keys

Your Claude credential and optional Gemini key are validated before they are saved and stored encrypted. When you replace a credential, the previous one is invalidated immediately.

Because Lyra runs on your own key, you control the budget and can rotate the key on your provider account at any time. See Add your Claude key.

Repository access

Lyra connects to your repo through the Lyra GitHub App, not a personal access token. You choose which repositories the app can reach, and you can disconnect at any time. Lyra works only through standard GitHub objects: branches, pull requests, issues, and review comments. See Connect your repository.

Nothing publishes without you

The most important control is the merge. Lyra opens pull requests and tags you, but she never merges. Nothing auto-publishes. Every post reaches your blog only when you merge it.

Data isolation

Your data is isolated per tenant, so each account's websites, posts, and settings are kept separate from every other account's.

Payment security

All payment runs through Stripe's hosted checkout and customer portal. Card details never touch Lyra. See Billing.

What's next