Security and data boundaries for runtime compliance.

Review supported deployment models, current technical controls, customer-data handling, procurement documents, and our certification roadmap.

Keep policy enforcement close to the workload.

Choose managed cloud, private cloud or VPC, on-premises, or air-gapped deployment according to your operating boundary.

Controls supported by the current service materials.

Encryption

API communications use TLS 1.2 or later. Stored keys use Fernet authenticated encryption (AES-128-CBC with HMAC-SHA256), and raw API keys are not stored.

Access control

API-key authentication, SHA-256 key hashing, optional per-key IP allowlisting, rate limits, and role-based access control support service boundaries.

Evidence integrity

Audit records are hash-chained with SHA-256 continuity fields so customers can verify record linkage.

Application protections

PII detection and masking, security headers, operational logging, and configurable deployment boundaries support defense in depth.

Minimize persistent content and make optional paths explicit.

Core evaluation

Query text is processed in transit and volatile memory. The audit store uses a one-way query fingerprint rather than full raw query text.

Customer-configured LLMs

Full query content reaches an LLM only when a customer enables BYOK AI Judge or an equivalent configured integration.

Training and analytics

Request-derived training or non-essential product analytics is opt-in. Customer data is not sold.

Implementation-level details and deployment-specific qualifications are in Data Practices.

Certification work is a roadmap, not a current attestation.

SOC 2 Type II initiation is planned as a company milestone. ISO 27001 certification is not currently held; any certification work remains planned and will only be represented as complete after an applicable independent audit. No statement on this page should be read as a current certification or attestation.