Security

What we do, and what we won't do, with your data.

We're an infrastructure layer. We forward your traffic, we meter it, and we get out of the way. This page is the short version; full SOC 2 type II reports and DPAs are available under NDA.

/ 01

We don't train on your traffic.

Prompts and completions that pass through idclinks are never used to train any model — ours, our upstream providers', or anyone else's. This is contractual, not just a stated preference.

/ 02

We don't log content by default.

Standard requests log metadata only: model, region, replica, token counts, latency, status. Prompt and completion bytes are not persisted. Customers who need a content audit log can opt-in explicitly per project.

/ 03

Zero-retention routes are first-class.

Set idc-no-retention: true on any request and we route to a pool where prompt and completion bytes never leave volatile memory. No disk, no cache, no audit trail beyond metadata.

/ 04

Data residency you can pin.

EU traffic stays in EU. Other regions are equally pinnable on Enterprise. We document the route in the response headers so you can verify, not just trust.

Compliance

The frameworks we hold ourselves to.

Framework Status Artifacts available
SOC 2 Type II in continuous audit Full report under NDA, latest audit window covers Nov 2025 – April 2026.
GDPR / UK GDPR compliant Standard contractual clauses, DPA, ROPA available.
CCPA / CPRA compliant Subject-access request workflow documented.
HIPAA BAA on request Available on Enterprise with dedicated capacity and zero-retention routes.
ISO 27001 target Q4 2026 Currently in surveillance audit; will share certification on issuance.
Practices

The day-to-day discipline.

Access

Least-privilege, with review.

All production access is gated by hardware-backed SSO and reviewed quarterly. Privileged sessions are recorded; reviewers rotate to avoid same-team approvals. Customer content is never accessed without a written ticket from the customer.

Encryption

In transit, at rest, end-to-end.

TLS 1.3 enforced on every external endpoint. Internal service-to-service traffic uses mutual TLS with rotating certificates. Persisted data — billing, metadata, audit logs — is encrypted at rest with envelope keys managed in a hardware security module.

Secrets

Short-lived. Auditable. Recoverable.

API keys are bcrypt-hashed at rest with a per-key salt. Customer keys are rotateable from the dashboard or the management API. We never email keys; we never log keys in full.

Vulnerability

External and internal pressure-testing.

Annual third-party penetration tests; continuous internal red-team exercises against the gateway and management API. Public disclosure program at security@idclinks.com — reports get a same-business-day acknowledgment.

Resilience

Multi-region, drilled quarterly.

Each routed region is independently sufficient for global traffic at degraded capacity. We run a full region-failure drill every quarter and publish the recovery timeline to customers on Scale and above.

Subprocessors

Who else touches your traffic.

Subprocessor changes are notified to customers 30 days in advance. The current list is documented in our DPA.

Subprocessor Purpose Region
Upstream model providersInference (per-request, per your model selection)Per region
Cloud infrastructureCompute, network, object storageUS, EU, APAC
Payment processorCard and ACH billingUS
Identity providerDashboard SSO and MFAUS
Email deliveryTransactional and incident notificationsUS

Reviewing us for procurement?

Send the security questionnaire to sales@idclinks.com. We share SOC 2 reports, DPAs, architecture diagrams, and penetration test summaries under mutual NDA.