# Security

This section explains how your JARVIS account is protected and how access can be restricted.

| Page | Covers |
| --- | --- |
| [Account Security](/jarvis/security/account-security/) | Authentication, sessions, passwords, data isolation |
| [Global Enforcement](/jarvis/security/global-enforcement/) | Account-wide access restrictions across SpaceKeep Labs |
| [Privacy](/jarvis/security/privacy/) | What JARVIS stores and who can see it |

## The short version

- Your account is protected by an authenticated session, established with a password or a linked
  sign-in provider.
- Conversations, memories, and tasks are scoped to your account. Other users cannot read them.
- Credentials, keys, and session tokens never appear in a JARVIS reply.
- Memory is off-switchable, and stored memories are individually editable and deletable.
- A restriction applied to your SpaceKeep Labs account applies to JARVIS too.

## Reporting a problem

If you believe your account has been compromised:

1. [Change your password](/jarvis/account/password/) — this ends every session on every device.
2. [Revoke your API keys](/jarvis/account/sessions/#api-keys).
3. Review your [conversations](/jarvis/features/conversations/) and
   [memories](/jarvis/features/memory/) for anything you do not recognise, and delete it.
4. Review [web lookup history](/jarvis/features/web-search/#activity-history) for unexpected
   activity.

For anything else, contact [SpaceKeep Labs support](https://spacekeep.dev) and include what you
observed.

## Related

- [JARVIS Policies](https://jarvis.spacekeep.dev/policy) — acceptable use
- [Account](/jarvis/account/) — settings, password, sessions, and keys
- [API Authentication](/jarvis/api/authentication/) — credential handling on the wire
