Trust Center

Security and compliance disclosure for enterprise procurement. Every claim is tagged with its verification status and review date.

Last reviewed
Scope
RouteAPI gateway and self-operated infrastructure
On this page
No training on customer data Established

Covers the RouteAPI gateway and routing layer. Verified 2026-09-10.

Request content zero retention Established

Request-body logging is off by default; engineering closure completed.

SOC 2 / ISO 27001 In progress

In application; we do not claim certification before reports exist. DPA available today.

Data flow

Select any step to see what data it handles, whether that data is stored, how long it is kept, and which region it sits in. The dashed steps are outside our control — request content leaves our infrastructure when it reaches the provider you selected.

Within RouteAPI controlOutside our control, third-party policies apply

Authenticates, checks quota, selects a channel, and proxies the request upstream.

Region
Hong Kong
Purpose
Authentication, quota enforcement, routing, billing metering
Last reviewed
2026-09-10
Prompts and model outputsRequest contentIn memory only
User, model, token usage, costBusiness metadataRetained for billing and reconciliation
request_id, status code, latencyOperational metadata30 days

Request-body logging exists as a configurable capability and is disabled by default. Zero retention is not published as a completed fact until the engineering closure and production configuration audit are signed off.

Data handling & retention

We separate request content from business metadata and operational metadata, because they have different retention rules. Not persisting request content does not mean we keep no data at all — billing and audit records are retained.

DataRetentionRegionStatus
Prompts, model outputs, uploaded filesRequest content·Request-body logging is disabled by default and verified by engineering closure.Not persistedHong KongEstablished
Billing and usage recordsBusiness metadataRetained for billing, reconciliation and auditHong KongEstablished
Request logs (metadata only)Operational metadata30 daysHong KongEstablished
Administrative audit eventsOperational metadataRetained for security auditHong KongEstablished
Database backupsBusiness metadata·Backups are stored encrypted; expired backups are purged automatically and restore is limited to authorized operators.Daily automated backups, 30-day rolling windowHong KongEstablished

Provider data policies

RouteAPI not training on your data does not extend to upstream providers. Each policy below is bound to a specific product or account type, because a provider's policy for one product often does not apply to the others. Channels we have not verified are shown as not verified rather than hidden.

ProviderTraining policyRetentionProcessing regionSource
OpenAIAPI platform (non-consumer)Not used for training30 days, then deletedUnited States and other regionsPolicy ↗
AnthropicClaude API (commercial terms)Not used for trainingNot persisted; logs retained briefly for abuse monitoringUnited States and other regionsPolicy ↗
GoogleGemini API / Vertex AI — differs by productNot used for trainingDiffers by product and tier; Vertex AI enterprise: not storedVaries by configuration; supports regional data residencyPolicy ↗
AWS BedrockBedrock runtimeNot used for trainingNot stored by AWS; depends on underlying model providerDepends on the configured AWS regionPolicy ↗
Azure OpenAI ServiceAzure OpenAI Service (enterprise)Not used for training30 days, then deletedDepends on the configured Azure regionPolicy ↗
Z.aiZ.ai platformNot used for trainingNot stored; logs retained for security monitoring onlySingaporePolicy ↗
Alibaba CloudDashScope / Bailian (enterprise)Not used for trainingNot stored; enterprise edition does not log promptsMainland China (multi-region)Policy ↗

Platform security

Established, in-progress and not-established controls are listed together. We would rather you see an accurate picture than a curated one — items marked pending verification are being confirmed against production before we describe them as done.

Organizational security

3
Audit loggingEstablished

High-risk administrative actions are recorded with actor, tenant and request identifiers. Retention period and access scope are being documented.

Verified 2026-09-10

Penetration testingNot established

No third-party penetration test has been performed. We will publish the scope and date once one is completed.

Pending verification

Incident responseEstablished

A security contact and internal escalation path are in place, covering notification boundaries and incident records.

Verified 2026-09-10

Access control

4
AuthenticationEstablished

Email verification, OAuth sign-in, and passkey/MFA support are available. Whether MFA is enforced for internal administrators is being confirmed.

Verified 2026-09-10

Access controlEstablished

Regular users, administrators, operations and tenant roles are separated with server-side authorization checks.

Verified 2026-09-10

API key handlingEstablished

Keys can be created, scoped and revoked in the console. User keys and upstream provider keys are stored server-side with restricted access.

Verified 2026-09-10

Periodic access reviewEstablished

A recurring least-privilege access review with a named owner is in place; administrator and operations permissions are reviewed periodically.

Verified 2026-09-10

Data security

2
Encryption in transit (TLS 1.3)Established

Client-to-gateway and gateway-to-provider connections use HTTPS with TLS 1.3 (TLS 1.2 minimum). HSTS is enabled on public endpoints.

Verified 2026-09-10

Encryption at rest (AES-256)Established

Database and backup volumes are encrypted at rest by the cloud provider using AES-256. Selected sensitive configuration values receive an additional layer of application-level AES-256-GCM encryption.

Customer API keys and upstream provider credentials are stored server-side with restricted access and are not additionally encrypted at the application layer. Upstream credentials can only be revealed by a platform root role, subject to step-up verification, rate limiting, and an audit record.

Verified 2026-09-10

Infrastructure security

5
Abuse preventionEstablished

Turnstile human verification and rate limiting are available on registration and sign-in flows.

Verified 2026-09-10

AvailabilityEstablished

Two nodes in Hong Kong, with channel retry, fallback and health probing. Same-region high availability — not cross-region disaster recovery.

Verified 2026-09-10

Vulnerability & patch managementIn progress

Dependency and base-image scanning is being established with defined severity tiers and remediation windows.

Pending verification

CDN / WAFIn progress

No CDN or WAF is currently in front of the service. Enabling one will add a subprocessor and update the data flow.

Pending verification

Backup & disaster recoveryEstablished

Daily automated backups in Hong Kong with a 30-day rolling window, stored encrypted with restore limited to authorized operators. Same-region recovery — cross-region disaster recovery is not claimed.

Verified 2026-09-10

Subprocessors

A subprocessor is a third party we pass data to in order to run the service. The entry that receives your request content is marked in the table — that is usually the entry enterprise reviews care about most.

CompanyPurposeLocationRequest content
OpenAI, Anthropic, Google, AWS Bedrock, Azure and other configured channelsUpstream AI providersModel inferenceSelected by youVaries by provider and channelReceives
Alibaba Cloud (Hong Kong)Cloud infrastructureDatabase, cache, logs, backupsAlways activeHong KongNo
StripePaymentsCard payments, subscriptions, webhooksConfigurableUnited States / EuropeNo
PayPalPaymentsAlternative payment channel, webhooksConfigurablePer PayPal regionNo
SMTP providerTransactional emailAccount verification, password reset, notificationsConfigurablePer SMTP providerNo
Google Tag ManagerWeb analyticsSite analytics and conversion attributionAlways activeGlobalNo
Cloudflare TurnstileAbuse preventionHuman verification on registration and sign-inConfigurableGlobal CDNNo
GoogleIdentity (OAuth)Third-party sign-inConfigurablePer OAuth providerNo

We will notify customers of subprocessor additions or changes. The notice period and objection window are confirmed in the DPA.

Compliance & enterprise

We state certification status exactly as it is. SOC 2 and ISO 27001 are in application and have not been issued; a DPA is available today. We will not describe ourselves as certified before the report exists.

Certifications and agreements

SOC 2In application. No SOC 2 report has been issued. SOC 2 is a CPA attestation report, not a certificate.In progress
ISO 27001In application. Certification has not been issued.In progress
DPAAvailable. We can execute a data processing agreement covering processing scope, subprocessors and signing process.Established
Penetration test reportNo third-party penetration test has been performed. We will publish the scope and date once one is completed.Not established

SOC 2 is an attestation report issued by a CPA firm, not a certificate. We will publish the report type and scope once it exists.

Provider and channel restrictions

Enterprise customers can request that their traffic be restricted to a specific set of providers and channels. This is delivered as a routing policy bound to your account, not as a physical node selector.

Region-level restrictions and per-customer failover policies are not available today. If your review requires either, contact us — we will tell you what is and is not possible before you commit to anything.

FAQ

Do you store my prompts and model outputs?

No. RouteAPI does not retain your prompts, model outputs or uploaded files after a request completes. Request content exists in memory only for as long as it takes to authenticate, route and proxy the request.

What we do retain is the metadata needed for billing and troubleshooting: the model used, token counts, cost, request ID, status and timestamp. Not retaining request content does not mean we hold no data at all.

Your request content is sent to the upstream provider you select, and that provider's own retention policy applies — see the provider policy table above.

Do you train models on customer data?

RouteAPI does not train its own models on customer data. This does not extend to upstream providers — your request is sent to the provider you select, and their training and retention policies apply. See the provider policy table above.

Where is my data processed and stored?

The gateway, database, cache, logs and backups are in Hong Kong. Request content is additionally sent to the upstream provider you select, which may process it in another region. Hong Kong deployment does not mean the entire chain stays in Hong Kong.

Are you SOC 2 or ISO 27001 certified?

Not yet. Both are in application and neither has been issued. We will not describe ourselves as certified or compliant before the report or certificate exists. A DPA is available today.

What happens to my data when I delete my account?

Account deletion removes your profile and credentials within 30 days. This includes:

  • Account information and authentication credentials
  • API keys and access tokens
  • Usage logs and request metadata associated with your account

Billing records (top-ups, charges, refunds) are retained for 5 years as required by Singapore tax and accounting law, then deleted. These records contain transaction amounts and dates, but not the content of your API calls.

Request and response content (prompts, completions, uploaded files) is not retained by the gateway under normal operation. We do not store your API call content.

For data export requests, contact us at support@routeapi.ai before deleting your account.

Need a questionnaire response or a DPA?

Enterprise review materials are shared through a review process. Email security@routeapi.ai — we usually reply within one business day.

Email security team