RootInference

Security

Your prompts pass through us. They are not our product.

RootInference sits in your inference path, so we treat prompt privacy as a routing constraint: no training on your data, configurable retention, and per-provider data-policy controls — all auditable.

Prompt & completion privacy

No training on your data

Your prompts and completions are never used to train models — not by us, and we request no-training and zero-retention terms from providers wherever available.

Configurable prompt logging

Choose full request logging, metadata-only (tokens, latency, cost — no content), or zero content retention per API key.

Data retention controls

Configurable retention windows for request logs; content and metadata retention are controlled independently.

Encryption in transit and at rest

TLS 1.2+ for all connections; AES-256 encryption for stored data and secrets.

Access & identity

Role-based access control

Owner, admin and member roles per organisation, with least-privilege defaults.

Single sign-on

SAML and OIDC SSO on Scale and Enterprise plans.

SCIM provisioning

Automated user lifecycle management for enterprise identity providers.

Scoped API keys

Per-key model allowlists, routing policies, spend caps and expiry dates — a leaked key is a bounded incident.

Provider data governance

Per-provider data policies

Set requirements — no training, zero retention, region — and routing only considers providers that meet them.

Provider allowlists

Restrict any key or organisation to an explicit set of providers; requests to others are refused, not rerouted.

Regional routing

Keep inference within chosen regions where providers offer regional endpoints, for latency and data-residency needs.

Request audit trail

Every request records model, provider, routing decision and cost in an administrator-visible audit log.

Platform & spend controls

Data isolation

Organisation data is logically isolated; enterprise deployments can add dedicated infrastructure.

Secret management

API keys are stored hashed; any provider credentials you bring are held in a dedicated secret store.

Budget alerts and hard caps

Spend limits per key and organisation stop runaway usage before it becomes an invoice surprise.

Audit logs

Administrator-visible logs for access, configuration changes and credit adjustments.

Compliance

Compliance roadmap

We describe our compliance posture precisely: certifications are stated as achieved only once audits complete.

SOC 2 Type IIIn progress
ISO 27001Roadmap
GDPRDesigned for
EU AI ActReadiness programme