Keep policy enforcement close to the workload.
Choose managed cloud, private cloud or VPC, on-premises, or air-gapped deployment according to your operating boundary.
Review supported deployment models, current technical controls, customer-data handling, procurement documents, and our certification roadmap.
Choose managed cloud, private cloud or VPC, on-premises, or air-gapped deployment according to your operating boundary.
API communications use TLS 1.2 or later. Stored keys use Fernet authenticated encryption (AES-128-CBC with HMAC-SHA256), and raw API keys are not stored.
API-key authentication, SHA-256 key hashing, optional per-key IP allowlisting, rate limits, and role-based access control support service boundaries.
Audit records are hash-chained with SHA-256 continuity fields so customers can verify record linkage.
PII detection and masking, security headers, operational logging, and configurable deployment boundaries support defense in depth.
Query text is processed in transit and volatile memory. The audit store uses a one-way query fingerprint rather than full raw query text.
Full query content reaches an LLM only when a customer enables BYOK AI Judge or an equivalent configured integration.
Request-derived training or non-essential product analytics is opt-in. Customer data is not sold.
Implementation-level details and deployment-specific qualifications are in Data Practices.
Service use, account duties, program terms, disclaimers, and liability boundaries.
Personal-data collection, use, retention, sharing, rights, and extension disclosures.
Technical data flows, storage model, optional LLM paths, telemetry, and deployment choices.
Controller and processor duties, subprocessors, safeguards, transfers, and deletion.
Availability, support, service-credit, maintenance, and performance terms.
SOC 2 Type II initiation is planned as a company milestone. ISO 27001 certification is not currently held; any certification work remains planned and will only be represented as complete after an applicable independent audit. No statement on this page should be read as a current certification or attestation.