burnlog

Security

Built to track spend, not secrets.

burnlog is designed for teams that need AI-agent cost visibility without collecting prompts, code, repo names, or paths.

Data boundary

Ingest accepts token counts, model/provider/source tags, timestamps, and opaque request ids, and nothing else — see the full field list in the privacy model. Prompt text, completions, file paths, working directories, shell output, tool output, repo names, and source code are not part of the schema.

Access controls

Spend controls

Audit and operations

Responsible disclosure

Report vulnerabilities to security@sxnalabs.com. Do not open public issues for exploitable bugs. Include the affected route/package, reproduction steps, impact, and suggested fix if known.

Last updated: 2026-06-14

Security posture and access controls · burnlog