Yixnova Rona

Designed for your own cloud

The setup hub handles identity and installation metadata. It does not serve as the chat backend for customer websites.

Cloud credentials are used during an authenticated, rate-limited installation request. AI keys are stored in your own Worker secrets. Lead contact fields use AES-GCM with a key generated for your installation.

Google and GitHub sign-in use authorization codes, state and PKCE. Provider accounts are not silently merged by matching email addresses.

Dashboard launch links expire after 60 seconds and can be used once. Runtime session cookies are HttpOnly. Tenant-scoped repositories and widget origin allowlists protect business data.

Yixnova Rona does not store a persistent Cloudflare deployment token. Keep the AI, email and encryption keys in your own account under your control.