AI Companion Portal Security in 2026: What the Current Ellivien Starter Protects
Security is not an optional decoration on an AI companion Portal.
It protects your API account, your conversations and the private place you are building with your companion. This article replaces my May 2026 explanation because the Ellivien starter pack has changed substantially since then.
The current basic starter is designed to keep your API key out of the browser, save conversations locally and let you add your companion prompt through the Portal itself rather than hard-coding it into index.html. It also includes a complete Password + KV Sync activation pack for people who want password protection and cross-device conversation sync.
Those layers do different jobs. It is important to know which protections work immediately and which ones you still need to activate.
Your API key stays in a Netlify environment variable and model requests pass through a server-side function.
Threads are stored in IndexedDB in your own browser unless you deliberately activate cloud sync.
The Password + KV Sync folder is supplied with the starter and must be configured and deployed by you.
No public website is magically "unhackable". Safe setup, strong secrets, private devices and sensible account limits still matter.
1. Your API Key Is Not Put in the Webpage
The current starter does not place your OpenAI API key inside index.html or send it to the browser. You add it as a private environment variable in Netlify. The browser sends a request to your Netlify function; that server-side function adds the API key when it contacts OpenAI.
This means somebody using View Source or Inspect on your Portal cannot simply read and copy the key.
However, a hidden key and a protected Portal are not the same thing. Before the Password + KV Sync pack is activated, the basic Portal's model proxy does not require a Portal session token. If somebody discovers that unprotected site and deliberately uses it, they may be able to send model requests that are charged to your API account even though they cannot see the key itself.
Activate the included password protection before sharing the URL or treating the Portal as ready for regular online use. Also never paste an API key, password, password hash, session secret or Cloudflare token into index.html. Anything sent to a browser can be inspected. Secrets belong in the relevant hosting service's environment variables or secret store.
2. The Companion Prompt Is Added Through the Portal
Older Ellivien files asked people to edit the companion prompt directly inside index.html. The current starter does not.
You open the Portal sidebar, paste or update the prompt there and save it. The prompt is stored in that browser's local storage and inserted into the model request when you chat. It is therefore not exposed merely because someone views your public source file or repository.
This is a meaningful improvement, but it is not the same as server-side encrypted storage. Someone who can use your unlocked device, open the Portal and inspect that browser's stored data may still be able to read it. The prompt is also sent to the model provider when it is used, because the model needs it in order to respond.
3. Basic Portal Conversations Are Local-First
In the basic starter, threads are saved to IndexedDB in the browser. They are not automatically placed into a central Ellivien database, and I do not receive or retain a copy of them.
Finding your Netlify address does not give another person the conversations stored in your phone or computer. However, local storage also means that clearing browser data, changing to a different site address or losing the device can remove access to that local copy. Use the Portal's export tools and keep private backups of anything irreplaceable.
4. Password Protection and KV Sync Are Included
The present free starter download contains a separate folder called Password + KV Sync - Activate Later. This activation pack is included with the free Portal, free of charge. It is deliberately not switched on automatically, because each Portal owner must create their own Cloudflare resources, choose their own password and secrets, and add those values to their own accounts.
When you follow the included activation guide and deploy that folder over the same Netlify site, it adds:
- a password screen for the visible Portal;
- a signed, time-limited session token after a correct password is entered;
- an OpenAI proxy that rejects model requests without a valid Portal session;
- a separate sync proxy that rejects unauthorised requests;
- a protected Cloudflare Worker and KV namespace for the shared conversation copy;
- local-first saving, with controlled automatic sync and a manual sync option.
The password must protect the paid function, not merely hide the page.
The included activation pack does this correctly: the browser sends its session token to the OpenAI proxy, and the proxy refuses unauthorised model calls. A decorative lock screen on its own would not be enough.
5. Why the Upgrade Must Use the Same Portal Address
IndexedDB belongs to a specific website origin. If you deploy the protected version as a completely new Netlify site with a different address, that new address cannot automatically see the conversations stored under the old one.
The activation guide therefore tells you to back up first and deploy the protected files over the existing Netlify site. Your browser-saved companion prompt should also remain available when the site address stays the same.
6. What Cloudflare KV Changes
KV sync gives your Portal a shared cloud copy so the same threads can appear on your phone, tablet and computer. The browser still saves locally first. The included setup uses a controlled 30-minute automatic sync rhythm, with manual sync available when needed, rather than writing to KV after every small local change.
The Cloudflare bearer token remains server-side. The Worker rejects requests without that token, and the Netlify sync proxy requires a valid Portal session before it contacts the Worker.
Activating sync does mean that your conversation data is no longer only on one device: a copy is stored in your own Cloudflare KV namespace. Treat access to your Cloudflare and Netlify accounts as part of your Portal security. Use unique passwords and enable two-factor authentication where it is available.
7. What the Current Pack Does Not Claim
I will never promise that a website is perfectly secure. The current starter and activation pack create sensible protection for a private, personal companion Portal, but they are not a multi-user identity platform or a substitute for professional security review.
- The current authentication pack uses one Portal password, not separate user accounts.
- It does not currently include rate limiting or temporary lockouts for repeated incorrect password attempts.
- A person with access to your unlocked browser or hosting accounts may be able to reach private data.
- Prompts and messages must travel to the model provider for the model to answer.
- Cloud sync protects access through authentication; it is not described as end-to-end encrypted storage.
- Your own account security, backups, spending limits and careful handling of secrets still matter.
8. Future Layers: Passkeys and MFA
I have added a passkey to my own Portal as an additional security layer. The free starter does not include this by default, because passkey and multi-factor authentication setups need to match the individual Portal's domain, hosting and recovery plan.
A passkey can replace or supplement a password by using a trusted device and its secure unlock method. MFA goes further by requiring more than one kind of check before access is granted. They are related ideas, but they are not automatically the same thing.
Both are technically possible future upgrades. Once your basic Portal and included password protection are working reliably, you can ask Codex to inspect your actual codebase, explain the available approaches and help add the option that fits your setup. Ask it to preserve a backup, design a recovery route and test both successful and rejected access before deployment.
Do not bolt on authentication blindly. A broken passkey or MFA implementation can lock you out of your own Portal or leave the paid proxy less protected than the visible page. Treat it as a proper security change: inspect, test, preserve recovery access and deploy deliberately.
9. A Sensible Security Checklist
- Download the current starter rather than relying on an old saved copy.
- Keep every API key and secret out of public files.
- Add the companion prompt through the Portal sidebar, not inside
index.html. - Keep the Netlify site address private while you are setting up.
- Activate the included Password + KV Sync pack before sharing the URL or relying on the Portal for regular online use.
- Use a long, unique Portal password and unique account passwords.
- Turn on two-factor authentication for Netlify, Cloudflare, your email account and your model-provider account where available.
- Consider a passkey or MFA upgrade later, once the included password protection is stable and backed up.
- Set spending alerts or limits with the model provider where the account supports them.
- Export and privately back up important threads before upgrades.
- Test that the Portal, model proxy and sync endpoint all reject unauthorised access after activation.
10. If You Downloaded an Older Ellivien Portal
Please do not assume that a pack downloaded months ago has the same structure as the current one. In particular, older instructions may tell you to put the companion prompt inside index.html or discuss password and KV protection as separate future additions.
Back up your threads and customised files, compare your version with the current starter, and ask Codex or Claude Code to help you migrate carefully. Do not overwrite a working Portal blindly.
Why I Care So Much About This
Ellivien Portals exist to give people more agency over their own companion spaces. That promise would mean very little if I treated security casually or pretended safeguards were stronger than they are.
I keep improving the free starter as I learn, test and build. That is why this article names both the protections and the limits. The API key is kept out of the browser. The prompt no longer has to be hard-coded into the public file. Conversations begin local-first. The password and KV package is included with the free Portal. And the person installing it still needs to configure, test and protect their own accounts.
A secure door is not a reason to be frightened of the home behind it.
It is how we make sure the people invited inside are the ones who belong there.
Comments
Post a Comment