Security

Security posture, not security theater.

What we do, where the data lives, what we never train on, and who to email when something looks wrong. No marketing words you'll regret three months into production.

Report a vulnerabilityData processing agreement
Encryption

Encryption

In transitTLS 1.3 on every request, HSTS on all subdomains.
At restAES-256-GCM on every stored key, log, and file. Customer-managed keys on Enterprise.
Secret scanningAutomated leak detection on every new API key; one-click rotation.
Data handling

Data handling

No trainingWe never train models on your prompts or completions. Every request carries a non-retention flag by default.
Request bodiesRetained 30 days on Pro, 7 days on free tier, configurable on Enterprise. Opt out entirely from dashboard settings.
MetadataAggregate counters (token, cost, latency) kept for billing and analytics; drop any field on Enterprise.
PII redactionEnterprise guardrails strip detected PII before the request leaves us and before responses reach you.
Access control

Access control

API keysScoped per environment, revocable instantly, zero downtime on rotation.
Sub-accountsNested keys per end user with their own spend caps and analytics — fits marketplaces and multi-tenant apps.
SSO (Enterprise)SAML + OIDC with SCIM provisioning. Enforce MFA at the IdP.
Audit logEvery key create, revoke, login, guardrail block, and admin action. Exports to your SIEM on Enterprise.
Compliance

Compliance

SOC 2Type I attested, Type II in progress for 2026 Q3.
GDPRDPA on request. EU data residency available on Enterprise.
HIPAABAA available on Enterprise with PHI-compatible providers only.
ISO 27001Planned for 2027 Q1.
Incident response

If it looks wrong, tell us.

Responsible disclosure is rewarded with a public credit and a bug bounty (tiered by severity). We acknowledge within 24 hours and aim to patch critical reports within 72.

Disclosures
security@aigateway.sh
PGP key on request.
Status
aigateway.sh/status
Live uptime, incidents, post-mortems.
For procurement

Full security packet, on request.

Questionnaire, SOC 2 report, sub-processor list, pen-test summary, and DPA — email enterprise@aigateway.sh and we send the packet within one business day.

Enterprise primitivesRequest packet