Security & Privacy

Privacy First

Your Data Stays Yours

shape

No Data Training

Your conversations, files, and generated content are never used to train AI models. What you create is yours alone.

shape

Self-Hosted Analytics

We run our own analytics. No Google Analytics, no Facebook Pixel, no third-party trackers watching your every move.

shape

No Data Selling

We don't sell your data. Period. Our business model is simple: you pay us for a service, not the other way around.

Account Security

Protected Access

shape

Multi-Factor Authentication

TOTP-based MFA with authenticator app support. Recovery codes included. Your account, double-locked.

shape

Encrypted Storage

API keys encrypted at rest with libsodium. Passwords hashed with bcrypt. Your secrets stay secret.

shape

Account Lockout

Automatic lockout after failed login attempts. Brute force protection built in. Bad actors get blocked.

shape

Session Invalidation

Change your password? All sessions invalidated instantly. Lost a device? One click logs out everywhere.

shape

API Key Security

256-bit cryptographically secure keys. Only hashes stored. Rotate anytime. Full control in your hands.

shape

CSRF Protection

Every state-changing request validated. Cross-site attacks blocked. Security headers enabled by default.

Compliance

Global Standards

GDPR

European Union

PIPEDA

Canada

LGPD

Brazil

PIPL

China

Infrastructure

Built Secure

shape

Nordic Servers

Infrastructure in Iceland and Finland. Strong privacy laws. Powered by geothermal and hydroelectric energy.

shape

TLS Everywhere

All connections encrypted in transit. HTTPS enforced. No exceptions. Your data travels safely.

shape

Isolated Processing

Your workloads don't mix with others. Dedicated processing. Clean separation between tenants.

Questions?

We're Happy to Talk Security

Have specific security requirements or compliance questions? Reach out.

Contact Us