Trust center

Security posture without borrowed badges.

See what is deployed, what remains contract-scoped, and exactly where customer and AI Gateway HQ responsibilities begin.

  • Implemented controls labeled explicitly
  • No certification claims before audit
  • Prompt bodies omitted from gateway telemetry
Working sandbox capture
A security control should show how it is configured.The working guardrail surface exposes request, response, and tool stages; signal families; MCP boundaries; rollout mode; and redaction or block behavior.
Noprompt persistence in gateway code
KMStenant-bound credential encryption
US-E1hosted production region
BYOKcustomers fund provider inference
Implemented

Tenant-scoped authorization

Tenant context is mandatory across current data access, queue, encryption, audit, and policy paths.

Implemented

Provider secret protection

The hosted production cell uses KMS encryption context per tenant and credential. Plaintext is short-lived and excluded from telemetry.

Implemented

Metadata-only telemetry

Gateway code does not persist prompt/response bodies or tool schemas, arguments, and results. Events contain identity, route, policy, bounded tool names/types/MCP hosts, usage, cost, and timing metadata.

Implemented baseline

Supply-chain controls

Protected GitHub OIDC deployments, signed release artifacts, reviewed infrastructure plans, CodeQL, dependency review, and release scanning gate production changes.

Assurance path

Architect now. Certify when justified.

A sound architecture can reduce later rework, but certification is never merely administrative: sustained operations, evidence, remediation, legal review, independent testing, and audit work still matter.

Now

Secure engineering baseline

Threat model, data inventory, least privilege, encryption, audit, incident response, backups, change evidence, vulnerability handling.

Revenue gate

Independent validation

Penetration test, policy review, vendor assessment, evidence sampling, legal and insurance readiness.

Contract gate

Formal assurance

SOC 2 audit program, BAAs where applicable, customer-specific mappings, contracted SLA, and private deployment review.

Current claims

AI Gateway HQ operates a hosted production gateway with published pricing and Stripe-hosted self-service billing. Managed Amazon Bedrock is limited to reviewed U.S. conversational models and requires purchased credit plus a reusable payment method. AI Gateway HQ does not currently claim SOC 2 certification, HIPAA compliance, PCI certification, FedRAMP authorization, or a general-availability SLA. Those commitments require the applicable contracts, operations, independent testing, and audit work.