Enterprise-Grade Security. By Default.
Your data is yours. We never train on your data without explicit consent. We offer Zero-Data-Retention, custom data residency, and full audit trails. Our security stack is built for the most demanding financial institutions.
SOC 2 Type II
Audited by Vanta. Covers Security, Availability, and Confidentiality. Report available under NDA.
ISO 27001
Certified by BSI. Covers the full ISMS. Annual recertification.
GDPR
Full GDPR compliance. EU data residency. SCCs available. DPA under NDA.
HIPAA (Eligible)
HIPAA-eligible. BAA available for healthcare customers. PHI encryption at rest and in transit.
Encryption
AES-256 at rest. TLS 1.3 in transit. Customer-managed keys (KMS) available on Enterprise tier.
SSO / SAML
SAML 2.0 SSO. SCIM provisioning. Role-based access control (RBAC). MFA enforcement.
PII Redaction
Real-time NER-based PII detection and masking. 12 entity types. Configurable per-project.
Data Residency
US-East, EU-West, APAC-Southeast. Pin your data to a specific region. Custom residency on Enterprise tier.
Audit Trail
Every token is traced. Every request is logged. Every action is attributed. Immutable audit log. Exportable to your SIEM.
Zero-Data-Retention
ZDR with model providers. Your data is deleted after inference. No training. No retention. Enterprise tier.
Where Your Data Goes
Your data transits our gateway for processing (PII redaction, caching, RAG). It is then sent to the model provider over TLS 1.3. With ZDR, the model provider deletes your data after inference. Your data is never stored on our servers unless you enable RAG or caching.
Get Our Security Package
SOC 2 report, ISO 27001 certificate, DPA, BAA, and security questionnaire - all available under NDA.