Security
Security architecture
Enterprise-grade security built into every layer.
Request security review packet →Encryption
At restAES-256; keys managed via HSM
In transitTLS 1.3; TLS 1.2 minimum enforced
Zero retention optionEnterprise accounts can disable all request/response logging
Key management
Key scopingPer-model, per-environment (dev/staging/prod), per spend limit
RotationZero-downtime rotation supported; old key active until explicitly revoked
IP allowlistingRestrict API access to specific CIDR ranges per key or per team
Logging & audit
Request logsModel ID, latency, token count, status code, user metadata per request
Audit trailImmutable log of all admin actions: key create/revoke, team changes, policy updates
ExportS3, GCS, or SIEM via webhook
Retention90-day hot; 1-year cold archive by default. Custom on request.
Access control
RBAC rolesOwner · Admin · Developer · Viewer; custom roles available
SSO / SAML 2.0Okta, Azure AD, or any OIDC provider
RevocationInstant; no propagation delay
Compliance
SOC 2 Type IIAudit in progress; controls documentation available under NDA
GDPR / DPAArticle 28 DPA available; sub-processor list included
CCPACovered in DPA
HIPAA / BAABAA available for covered entities on enterprise contract
Pen testingAnnual third-party; summary available on request