EU-hosted control plane
Application services, gateway configuration, encrypted credentials, and retained request metadata are deployed in an EU Azure region.
Technical trust disclosure
This page describes the product's technical controls. It is not a contractual SLA, privacy policy, or data-processing agreement.
Application services, gateway configuration, encrypted credentials, and retained request metadata are deployed in an EU Azure region.
Prompts and responses are sent to the model provider selected by the customer. Processing location therefore depends on that provider account, endpoint, and region.
The product retains request identifiers, model, timing, token, cost, retry, and normalized error metadata. It does not retain prompts or model responses.
Each provider credential is envelope-encrypted. Its data key is wrapped by key material held in Azure Key Vault; plaintext credentials are not stored in PostgreSQL.
Tenant-scoped reads filter by organisation in SQL. Roles gate mutations, and security-sensitive changes are written to the organisation audit trail.
The commercial beta is single-region and currently runs one web replica. Contractual availability, residency, and support commitments require a separate signed agreement.
Operational dependencies