Security
Your prompts pass through us. They are not our product.
RootInference sits in your inference path, so we treat prompt privacy as a routing constraint: no training on your data, configurable retention, and per-provider data-policy controls — all auditable.
Prompt & completion privacy
No training on your data
Your prompts and completions are never used to train models — not by us, and we request no-training and zero-retention terms from providers wherever available.
Configurable prompt logging
Choose full request logging, metadata-only (tokens, latency, cost — no content), or zero content retention per API key.
Data retention controls
Configurable retention windows for request logs; content and metadata retention are controlled independently.
Encryption in transit and at rest
TLS 1.2+ for all connections; AES-256 encryption for stored data and secrets.
Access & identity
Role-based access control
Owner, admin and member roles per organisation, with least-privilege defaults.
Single sign-on
SAML and OIDC SSO on Scale and Enterprise plans.
SCIM provisioning
Automated user lifecycle management for enterprise identity providers.
Scoped API keys
Per-key model allowlists, routing policies, spend caps and expiry dates — a leaked key is a bounded incident.
Provider data governance
Per-provider data policies
Set requirements — no training, zero retention, region — and routing only considers providers that meet them.
Provider allowlists
Restrict any key or organisation to an explicit set of providers; requests to others are refused, not rerouted.
Regional routing
Keep inference within chosen regions where providers offer regional endpoints, for latency and data-residency needs.
Request audit trail
Every request records model, provider, routing decision and cost in an administrator-visible audit log.
Platform & spend controls
Data isolation
Organisation data is logically isolated; enterprise deployments can add dedicated infrastructure.
Secret management
API keys are stored hashed; any provider credentials you bring are held in a dedicated secret store.
Budget alerts and hard caps
Spend limits per key and organisation stop runaway usage before it becomes an invoice surprise.
Audit logs
Administrator-visible logs for access, configuration changes and credit adjustments.
Compliance
Compliance roadmap
We describe our compliance posture precisely: certifications are stated as achieved only once audits complete.