TensorProxyEU control plane

Technical trust disclosure

Clear boundaries around what the gateway stores and where traffic goes.

This page describes the product's technical controls. It is not a contractual SLA, privacy policy, or data-processing agreement.

EU-hosted control plane

Application services, gateway configuration, encrypted credentials, and retained request metadata are deployed in an EU Azure region.

Provider processing is separate

Prompts and responses are sent to the model provider selected by the customer. Processing location therefore depends on that provider account, endpoint, and region.

Metadata-only retention

The product retains request identifiers, model, timing, token, cost, retry, and normalized error metadata. It does not retain prompts or model responses.

Encrypted provider credentials

Each provider credential is envelope-encrypted. Its data key is wrapped by key material held in Azure Key Vault; plaintext credentials are not stored in PostgreSQL.

Tenant and activity controls

Tenant-scoped reads filter by organisation in SQL. Roles gate mutations, and security-sensitive changes are written to the organisation audit trail.

Current service boundary

The commercial beta is single-region and currently runs one web replica. Contractual availability, residency, and support commitments require a separate signed agreement.

Operational dependencies

Services involved in delivery

Microsoft Azure
EU-hosted application, database, secrets, and operational telemetry.
Stripe
Subscription checkout, invoices, tax handling, and the billing portal.
Resend
Transactional account, invitation, payment, and budget email delivery.
Customer-selected model providers
Inference processing using credentials and provider regions controlled by the customer.