API keys
Keys should be stored server-side only. Project keys are the beta default; team keys and scoped keys are roadmap items.
Security
Trust starts by being specific. This page avoids fake certifications and names the controls, beta limits, and roadmap items buyers will ask about.
Keys should be stored server-side only. Project keys are the beta default; team keys and scoped keys are roadmap items.
Request metadata is needed for billing, abuse prevention, debugging, and routing receipts. Reduced-log modes are planned.
Prompts may be routed to eligible model providers according to the selected policy and plan boundaries.
DPA, subprocessors, retention policy, SSO/RBAC, and audit logs should be published before enterprise motion.
Security promises