Compliance

Security and compliance

What we apply, what we do not have, and what we will sign. The middle section is the one most provider pages leave out.

What we apply

These are the measures we actually run today. Each one is something you can ask us to evidence in writing during procurement.

Encryption in transit

Traffic to and from the endpoint we issue uses TLS. Keys are transmitted over the same channel and are never sent by plain email.

  • Applied
  • TLS
  • No keys by email

Access control

Keys are issued per customer, scoped to what that customer needs, and revocable on request. We do not share one key between accounts.

  • Applied
  • Per customer
  • Revocable

Least privilege on our side

The people who can reach your account settings are the people who need to, and the list is short enough to name.

  • Applied
  • Short list
  • Nameable

No sale of data

We do not sell the data you send through the API, and we do not use it to build a competing product.

  • Not done
  • No resale
  • No competing product

Deletion on exit

When the agreement ends, what happens to the data is set out in the data processing agreement rather than left to interpretation.

  • Written down
  • In the DPA
  • Not left open

What we do not have

No certification badge

We do not hold ISO 27001. We do not hold SOC 2. We have no compliance logo to put in the footer, and there is no audit report we can hand to your security team. The certifications page lists this in full, deliberately, because a grayed-out badge would imply we are on our way to one, and we are not going to imply that.

  • Not held
  • ISO 27001
  • SOC 2
  • No audit report

Where to stop

If a certification is a hard requirement in your procurement process, this is the point at which to stop, and we would rather you stopped here than three weeks from now.

  • Say it now
  • Hard requirement
  • Stop here

Data protection, in practice

Personal data can pass through

Depending on what you build, the content you send to the model may contain personal data — a name and address on an invoice, for example. We process it to serve your requests. What we may and may not do with it is set out in the agreement.

  • Processed
  • To serve your requests
  • Terms in the agreement

Two documents, not one

Our privacy policy covers the data we collect through this website. That is a separate matter from the data you send through the API, and the two should not be read as one document.

  • Separate
  • Site data
  • API data

Residency and paperwork

Where your data is processed

The model runs on the provider's infrastructure, which means processing happens where that provider operates, not in a facility of ours. If you have residency requirements — a need for data to be processed in a particular jurisdiction, or not to leave one — tell us before you commit. We will confirm in writing what we can and cannot support rather than assume.

  • Tell us early
  • Provider's locations
  • Confirmed in writing

Documents we will sign

We will sign a data processing agreement, and we will work through your security questionnaire with honest answers. Tell us what your legal and security teams need to see, and we will send a draft to work from.

  • Will sign
  • DPA
  • Security questionnaire

Last reviewed: 2 October 2026. This page describes our practices; the binding commitments are those in the agreement signed with your organization.

COMPLIANCE · WHAT ACTUALLY APPLIES

Diagram of the flow: three stages connected by arrows, with the middle stage highlighted.

THE LAW

GDPR and CCPA

as they apply to a controller-processor chain

THE CONTRACT

A DPA we can sign

with sub-processors named in writing

THE RECORD

What we keep, and where

deletion terms written into the agreement

  • No ISO badge, no SOC 2 report — we say so
  • Sub-processors named in the DPA
  • Ask for the documents your legal team needs
What we apply, what we do not hold, and what we will sign.Diagram of the process. Not a screenshot.

Tell us what you're running.

Send us your monthly volume and what you use today. We usually reply within one business day with a price and a named contact.