Security & trust

A gateway sees your traffic, so it owes you precision about what it does — and refuses to do — with it. This page is the plain-language version; the privacy policy is the formal one.

Data handling

What we see, what we keep

  • No training on your data, ever. Pure routing is the product. We don't train models, we don't sell data, and providers receive your request under their API terms, not ours.
  • No prompt retention by the gateway. Request and response bodies transit; the ledger stores metadata — model, token counts, latency, exact cost, trace ID — not content.
  • Private models never leave your network. Device-agent inference happens inside your VPC over an outbound-only mTLS tunnel; only routing metadata reaches the control plane.
  • Caches are tenant-scoped. Exact-match and semantic caches are per-organization. There is no cross-tenant cache.
  • Hosted in Canada. Control plane and ledger live in Montréal, designed for Canadian privacy law and the GDPR, with enterprise residency options.

Infrastructure

How the gateway protects itself

  • Encryption everywhere: TLS 1.3 in transit, AES-256 at rest for the ledger and configuration, mTLS with pinned per-agent identities for device-agent tunnels.
  • Least-privilege keys: keys are assigned to named users, scoped by model locks and budgets, and revocable individually — including each agent's tunnel identity.
  • Blast-radius design: burnable prepaid keys fence spend before it happens; the kill switch bounds runaway behavior in minutes, not billing cycles.
  • Audit trail: every call, budget change, lock change and breaker trip is an exportable ledger event.

Responsible disclosure

Found something? Tell us first.

Report vulnerabilities to [email protected] with steps to reproduce. We acknowledge within one business day, keep you updated through the fix, credit researchers who want credit, and never pursue good-faith research. Please avoid accessing other customers' data and give us reasonable time before publishing.

Compliance roadmap: a SOC 2 Type II audit is scheduled with the console launch; the DPA, subprocessor list and pen-test summaries will be available under NDA for enterprise agreements. Ask via the contact page.

Security questions before you route production traffic?

Bring your questionnaire. We answer them for a living now.