Enterprise Security Without Enterprise Complexity
Your data stays yours. Zero AI training. Full compliance. Always.
Zero Training on Your Data
None of our 6 AI providers use API data for model training. Your conversations, documents, and customer data are never used to improve foundation models.
| Provider | API Data Used for Training? | HIPAA Eligible | BAA Available |
|---|---|---|---|
| Anthropic Claude | No (by default) | Yes (Enterprise) | Yes |
| OpenAI | No (by default, since March 2023) | No | No |
| Google Vertex AI | No (by default) | Yes | Yes |
| AWS Bedrock | No (by default) | Yes | Yes |
| Azure OpenAI | No (by default) | Yes | Yes |
| DeepSeek | No (by default) | No | No |
Security Pillars
Four layers of protection for your data, users, and infrastructure.
Data Encryption
AES-256 encryption at rest, TLS 1.3 for all data in transit. API keys encrypted with per-organization salts.
- AES-256 encryption at rest
- TLS 1.3 in transit
- Encrypted API key storage
- Secure key rotation
Access Control
Hierarchical RBAC with organization isolation. Every query is scoped to the requesting organization.
- System Admin -> Org Admin -> Dept Manager -> Member
- Organization-scoped isolation
- Department-level permissions
- Full audit logging
Compliance
Built for regulated industries. HIPAA-eligible infrastructure with GDPR data handling and SOC 2 alignment.
- HIPAA-eligible (via Bedrock/Azure)
- GDPR-compliant data handling
- SOC 2 Type II aligned
- Data residency options
Infrastructure
Multi-region deployment with connection pooling and automatic failover. 99.9% uptime SLA standard.
- 99.9% uptime SLA
- PostgreSQL connection pooling (100 concurrent)
- Redis caching layer
- Docker/Kubernetes deployment
HIPAA-Eligible by Design
For healthcare organizations that need BAA coverage, we recommend deploying with AWS Bedrock as the primary AI provider. Data stays within your AWS account, and the BAA is included with the AWS BAA addendum.
Azure OpenAI and Google Vertex AI are also HIPAA-eligible alternatives with regional data residency options.
How Data Flows
No data is stored by the AI provider. No training. API calls only.
Recommended HIPAA Configuration
Preferred. Data stays in your AWS account. BAA included with AWS BAA addendum.
Microsoft environment. Regional data residency. BAA available.
GCP ecosystem. Enterprise data isolation. BAA available.
Key Point
All 6 providers guarantee that API data is never used for model training. This is handled at the provider level -- no application code changes required. Simply sign the appropriate BAA with your chosen provider.
Have compliance questions?
Talk to our security team about HIPAA, GDPR, SOC 2, data residency, and custom compliance requirements.
Talk to Security Team