Security

Security architecture

Enterprise-grade security built into every layer.

Request security review packet →

Encryption

At restAES-256; keys managed via HSM
In transitTLS 1.3; TLS 1.2 minimum enforced
Zero retention optionEnterprise accounts can disable all request/response logging

Key management

Key scopingPer-model, per-environment (dev/staging/prod), per spend limit
RotationZero-downtime rotation supported; old key active until explicitly revoked
IP allowlistingRestrict API access to specific CIDR ranges per key or per team

Logging & audit

Request logsModel ID, latency, token count, status code, user metadata per request
Audit trailImmutable log of all admin actions: key create/revoke, team changes, policy updates
ExportS3, GCS, or SIEM via webhook
Retention90-day hot; 1-year cold archive by default. Custom on request.

Access control

RBAC rolesOwner · Admin · Developer · Viewer; custom roles available
SSO / SAML 2.0Okta, Azure AD, or any OIDC provider
RevocationInstant; no propagation delay

Compliance

SOC 2 Type IIAudit in progress; controls documentation available under NDA
GDPR / DPAArticle 28 DPA available; sub-processor list included
CCPACovered in DPA
HIPAA / BAABAA available for covered entities on enterprise contract
Pen testingAnnual third-party; summary available on request