# Security

Access to the direct AutoCoder API is secured by three layers that work together:

- **Firewall**: network-level protection in front of the service.
- **TLS**: every request travels over an encrypted HTTPS connection.
- **API key**: a per-customer key sent in the `x-api-key` header. The key scopes every request to your organization, so your data stays isolated from every other customer on each call.

```http
x-api-key: <your-api-key>
```

Your Hank.ai representative provisions the key for your organization. Treat it like a password. Keep it server-side. Do not commit it to source control. Rotate it through your representative if you suspect exposure.

For questions about protected health information (PHI) handling, business associate agreements, and data practices, see the [Trust and data practices](/trust) page.
