On this page
Covers the RouteAPI gateway and routing layer. Verified 2026-09-10.
Request-body logging is off by default; engineering closure completed.
In application; we do not claim certification before reports exist. DPA available today.
Data flow
Select any step to see what data it handles, whether that data is stored, how long it is kept, and which region it sits in. The dashed steps are outside our control — request content leaves our infrastructure when it reaches the provider you selected.
Sends requests over HTTPS/TLS using a RouteAPI API key.
API keys must not be embedded in front-end bundles or committed to source control.
Authenticates, checks quota, selects a channel, and proxies the request upstream.
Request-body logging exists as a configurable capability and is disabled by default. Zero retention is not published as a completed fact until the engineering closure and production configuration audit are signed off.
Runs inference on the request content. Policies differ per provider, product and account.
RouteAPI not training on customer data does not imply that upstream providers do not. Each channel must be verified separately.
The model output is streamed or returned to your application.
Streaming interruptions, retries and upstream errors are separate code paths and are covered by the same zero-retention verification scope.
Data handling & retention
We separate request content from business metadata and operational metadata, because they have different retention rules. Not persisting request content does not mean we keep no data at all — billing and audit records are retained.
| Data | Retention | Region | Status |
|---|---|---|---|
| Prompts, model outputs, uploaded filesRequest content·Request-body logging is disabled by default and verified by engineering closure. | Not persisted | Hong Kong | Established |
| Billing and usage recordsBusiness metadata | Retained for billing, reconciliation and audit | Hong Kong | Established |
| Request logs (metadata only)Operational metadata | 30 days | Hong Kong | Established |
| Administrative audit eventsOperational metadata | Retained for security audit | Hong Kong | Established |
| Database backupsBusiness metadata·Backups are stored encrypted; expired backups are purged automatically and restore is limited to authorized operators. | Daily automated backups, 30-day rolling window | Hong Kong | Established |
Provider data policies
RouteAPI not training on your data does not extend to upstream providers. Each policy below is bound to a specific product or account type, because a provider's policy for one product often does not apply to the others. Channels we have not verified are shown as not verified rather than hidden.
| Provider | Training policy | Retention | Processing region | Source |
|---|---|---|---|---|
| OpenAIAPI platform (non-consumer) | Not used for training | 30 days, then deleted | United States and other regions | Policy ↗ |
| AnthropicClaude API (commercial terms) | Not used for training | Not persisted; logs retained briefly for abuse monitoring | United States and other regions | Policy ↗ |
| GoogleGemini API / Vertex AI — differs by product | Not used for training | Differs by product and tier; Vertex AI enterprise: not stored | Varies by configuration; supports regional data residency | Policy ↗ |
| AWS BedrockBedrock runtime | Not used for training | Not stored by AWS; depends on underlying model provider | Depends on the configured AWS region | Policy ↗ |
| Azure OpenAI ServiceAzure OpenAI Service (enterprise) | Not used for training | 30 days, then deleted | Depends on the configured Azure region | Policy ↗ |
| Z.aiZ.ai platform | Not used for training | Not stored; logs retained for security monitoring only | Singapore | Policy ↗ |
| Alibaba CloudDashScope / Bailian (enterprise) | Not used for training | Not stored; enterprise edition does not log prompts | Mainland China (multi-region) | Policy ↗ |
Platform security
Established, in-progress and not-established controls are listed together. We would rather you see an accurate picture than a curated one — items marked pending verification are being confirmed against production before we describe them as done.
Organizational security
3Audit loggingEstablished
High-risk administrative actions are recorded with actor, tenant and request identifiers. Retention period and access scope are being documented.
Penetration testingNot established
No third-party penetration test has been performed. We will publish the scope and date once one is completed.
Incident responseEstablished
A security contact and internal escalation path are in place, covering notification boundaries and incident records.
Access control
4AuthenticationEstablished
Email verification, OAuth sign-in, and passkey/MFA support are available. Whether MFA is enforced for internal administrators is being confirmed.
Access controlEstablished
Regular users, administrators, operations and tenant roles are separated with server-side authorization checks.
API key handlingEstablished
Keys can be created, scoped and revoked in the console. User keys and upstream provider keys are stored server-side with restricted access.
Periodic access reviewEstablished
A recurring least-privilege access review with a named owner is in place; administrator and operations permissions are reviewed periodically.
Data security
2Encryption in transit (TLS 1.3)Established
Client-to-gateway and gateway-to-provider connections use HTTPS with TLS 1.3 (TLS 1.2 minimum). HSTS is enabled on public endpoints.
Encryption at rest (AES-256)Established
Database and backup volumes are encrypted at rest by the cloud provider using AES-256. Selected sensitive configuration values receive an additional layer of application-level AES-256-GCM encryption.
Customer API keys and upstream provider credentials are stored server-side with restricted access and are not additionally encrypted at the application layer. Upstream credentials can only be revealed by a platform root role, subject to step-up verification, rate limiting, and an audit record.
Infrastructure security
5Abuse preventionEstablished
Turnstile human verification and rate limiting are available on registration and sign-in flows.
AvailabilityEstablished
Two nodes in Hong Kong, with channel retry, fallback and health probing. Same-region high availability — not cross-region disaster recovery.
Vulnerability & patch managementIn progress
Dependency and base-image scanning is being established with defined severity tiers and remediation windows.
CDN / WAFIn progress
No CDN or WAF is currently in front of the service. Enabling one will add a subprocessor and update the data flow.
Backup & disaster recoveryEstablished
Daily automated backups in Hong Kong with a 30-day rolling window, stored encrypted with restore limited to authorized operators. Same-region recovery — cross-region disaster recovery is not claimed.
Subprocessors
A subprocessor is a third party we pass data to in order to run the service. The entry that receives your request content is marked in the table — that is usually the entry enterprise reviews care about most.
| Company | Purpose | Location | Request content |
|---|---|---|---|
| OpenAI, Anthropic, Google, AWS Bedrock, Azure and other configured channelsUpstream AI providers | Model inferenceSelected by you | Varies by provider and channel | Receives |
| Alibaba Cloud (Hong Kong)Cloud infrastructure | Database, cache, logs, backupsAlways active | Hong Kong | No |
| StripePayments | Card payments, subscriptions, webhooksConfigurable | United States / Europe | No |
| PayPalPayments | Alternative payment channel, webhooksConfigurable | Per PayPal region | No |
| SMTP providerTransactional email | Account verification, password reset, notificationsConfigurable | Per SMTP provider | No |
| Google Tag ManagerWeb analytics | Site analytics and conversion attributionAlways active | Global | No |
| Cloudflare TurnstileAbuse prevention | Human verification on registration and sign-inConfigurable | Global CDN | No |
| GoogleIdentity (OAuth) | Third-party sign-inConfigurable | Per OAuth provider | No |
We will notify customers of subprocessor additions or changes. The notice period and objection window are confirmed in the DPA.
Compliance & enterprise
We state certification status exactly as it is. SOC 2 and ISO 27001 are in application and have not been issued; a DPA is available today. We will not describe ourselves as certified before the report exists.
Certifications and agreements
SOC 2 is an attestation report issued by a CPA firm, not a certificate. We will publish the report type and scope once it exists.
Enterprise materials
Available on request. Documents are shared through a review process rather than public download.
- One-page Security Overview
- Data flow diagram
- Data fields and purpose inventory
- Retention and deletion policy
- Subprocessor list
- Data processing agreement (DPA)
- Security questionnaire response
Provider and channel restrictions
Enterprise customers can request that their traffic be restricted to a specific set of providers and channels. This is delivered as a routing policy bound to your account, not as a physical node selector.
Region-level restrictions and per-customer failover policies are not available today. If your review requires either, contact us — we will tell you what is and is not possible before you commit to anything.
FAQ
Do you store my prompts and model outputs?
No. RouteAPI does not retain your prompts, model outputs or uploaded files after a request completes. Request content exists in memory only for as long as it takes to authenticate, route and proxy the request.
What we do retain is the metadata needed for billing and troubleshooting: the model used, token counts, cost, request ID, status and timestamp. Not retaining request content does not mean we hold no data at all.
Your request content is sent to the upstream provider you select, and that provider's own retention policy applies — see the provider policy table above.
Do you train models on customer data?
RouteAPI does not train its own models on customer data. This does not extend to upstream providers — your request is sent to the provider you select, and their training and retention policies apply. See the provider policy table above.
Where is my data processed and stored?
The gateway, database, cache, logs and backups are in Hong Kong. Request content is additionally sent to the upstream provider you select, which may process it in another region. Hong Kong deployment does not mean the entire chain stays in Hong Kong.
Are you SOC 2 or ISO 27001 certified?
Not yet. Both are in application and neither has been issued. We will not describe ourselves as certified or compliant before the report or certificate exists. A DPA is available today.
What happens to my data when I delete my account?
Account deletion removes your profile and credentials within 30 days. This includes:
- Account information and authentication credentials
- API keys and access tokens
- Usage logs and request metadata associated with your account
Billing records (top-ups, charges, refunds) are retained for 5 years as required by Singapore tax and accounting law, then deleted. These records contain transaction amounts and dates, but not the content of your API calls.
Request and response content (prompts, completions, uploaded files) is not retained by the gateway under normal operation. We do not store your API call content.
For data export requests, contact us at support@routeapi.ai before deleting your account.
Enterprise review materials are shared through a review process. Email security@routeapi.ai — we usually reply within one business day.
