Security & trust
A gateway sees your traffic, so it owes you precision about what it does — and refuses to do — with it. This page is the plain-language version; the privacy policy is the formal one.
Data handling
What we see, what we keep
- No training on your data, ever. Pure routing is the product. We don't train models, we don't sell data, and providers receive your request under their API terms, not ours.
- No prompt retention by the gateway. Request and response bodies transit; the ledger stores metadata — model, token counts, latency, exact cost, trace ID — not content.
- Private models never leave your network. Device-agent inference happens inside your VPC over an outbound-only mTLS tunnel; only routing metadata reaches the control plane.
- Caches are tenant-scoped. Exact-match and semantic caches are per-organization. There is no cross-tenant cache.
- Hosted in Canada. Control plane and ledger live in Montréal, designed for Canadian privacy law and the GDPR, with enterprise residency options.
Infrastructure
How the gateway protects itself
- Encryption everywhere: TLS 1.3 in transit, AES-256 at rest for the ledger and configuration, mTLS with pinned per-agent identities for device-agent tunnels.
- Least-privilege keys: keys are assigned to named users, scoped by model locks and budgets, and revocable individually — including each agent's tunnel identity.
- Blast-radius design: burnable prepaid keys fence spend before it happens; the kill switch bounds runaway behavior in minutes, not billing cycles.
- Audit trail: every call, budget change, lock change and breaker trip is an exportable ledger event.
Responsible disclosure
Found something? Tell us first.
Report vulnerabilities to [email protected] with steps to reproduce. We acknowledge within one business day, keep you updated through the fix, credit researchers who want credit, and never pursue good-faith research. Please avoid accessing other customers' data and give us reasonable time before publishing.
Compliance roadmap: a SOC 2 Type II audit is scheduled with the console launch; the DPA, subprocessor list and pen-test summaries will be available under NDA for enterprise agreements. Ask via the contact page.
Security questions before you route production traffic?
Bring your questionnaire. We answer them for a living now.