Encryption in transit
Traffic to and from the endpoint we issue uses TLS. Keys are transmitted over the same channel and are never sent by plain email.
What we apply, what we do not have, and what we will sign. The middle section is the one most provider pages leave out.
These are the measures we actually run today. Each one is something you can ask us to evidence in writing during procurement.
Traffic to and from the endpoint we issue uses TLS. Keys are transmitted over the same channel and are never sent by plain email.
Keys are issued per customer, scoped to what that customer needs, and revocable on request. We do not share one key between accounts.
The people who can reach your account settings are the people who need to, and the list is short enough to name.
We do not sell the data you send through the API, and we do not use it to build a competing product.
When the agreement ends, what happens to the data is set out in the data processing agreement rather than left to interpretation.
We do not hold ISO 27001. We do not hold SOC 2. We have no compliance logo to put in the footer, and there is no audit report we can hand to your security team. The certifications page lists this in full, deliberately, because a grayed-out badge would imply we are on our way to one, and we are not going to imply that.
If a certification is a hard requirement in your procurement process, this is the point at which to stop, and we would rather you stopped here than three weeks from now.
Depending on what you build, the content you send to the model may contain personal data — a name and address on an invoice, for example. We process it to serve your requests. What we may and may not do with it is set out in the agreement.
Our privacy policy covers the data we collect through this website. That is a separate matter from the data you send through the API, and the two should not be read as one document.
The model runs on the provider's infrastructure, which means processing happens where that provider operates, not in a facility of ours. If you have residency requirements — a need for data to be processed in a particular jurisdiction, or not to leave one — tell us before you commit. We will confirm in writing what we can and cannot support rather than assume.
We will sign a data processing agreement, and we will work through your security questionnaire with honest answers. Tell us what your legal and security teams need to see, and we will send a draft to work from.
Last reviewed: 2 October 2026. This page describes our practices; the binding commitments are those in the agreement signed with your organization.
COMPLIANCE · WHAT ACTUALLY APPLIES
THE LAW
GDPR and CCPA
as they apply to a controller-processor chain
THE CONTRACT
A DPA we can sign
with sub-processors named in writing
THE RECORD
What we keep, and where
deletion terms written into the agreement
Send us your monthly volume and what you use today. We usually reply within one business day with a price and a named contact.