Legal · Security

Security

Last updated · 30 September 2026 Entity · Sociaro Baltic OÜ Contact · dpo@sociaro.com

What we run, what we store, and what we deliberately do not — written so your security team can check it rather than take our word for it.

Where it runs

The gateway, its database and all usage accounting run on dedicated servers in Helsinki, Finland. Network access reaches them through Cloudflare; nothing else sits in the request path.

Inference is a separate decision, and it is yours. An account runs in EU-only mode, where requests are served exclusively by EU inference endpoints, or in global mode, which opens the full catalogue. The region each request was served from is recorded and appears in your usage data, so the choice is auditable rather than a promise.

What we store, and what we deliberately do not

Request content is not written to our database. Prompts, system messages, reference media and model responses pass through to the provider and back to you.

We store what billing needs: model, provider, region, token counts, price, status, latency, timestamp, and any attribution tag you send yourself. For asynchronous media jobs we also keep the scalar pricing parameters — resolution, duration, image count — because the price cannot be finalised without them. No prompts, no URLs, no free text.

The same discipline is applied to alerting. Operational alerts are restricted to content-free types; the alert categories that embed request text are switched off deliberately rather than relying on redaction to strip them.

Keys and credentials

What the API does not disclose

The model catalogue served to clients is filtered. Upstream endpoints, provider credentials, internal transport identifiers and routing detail are removed from public responses, and the filter fails closed on any shape it does not recognise — an unexpected response is emptied rather than passed through. Clients see pricing and capabilities; they do not see how a model is reached.

Host and network

Accounting integrity

Every call is metered at the point it completes and written to an append-only spend record. Usage figures you see in the console are the figures we invoice from, drawn from the same table — there is no second set of numbers. Where a request fails upstream, it is not billed.

Incidents

If a personal data breach affects you we will tell you without undue delay, and notify the supervisory authority within 72 hours as Article 33 requires. Security contact: dpo@sociaro.com.

What we do not claim

We hold no ISO 27001 or SOC 2 certification, and we do not describe ourselves as certified against either. The controls above are what we operate, stated so you can verify them rather than take them on trust.

Once a request leaves the gateway for a model provider, that provider's own security posture applies. Their policies are linked on the sub-processors page.

Questions and reviews

We answer security questionnaires and sign DPAs. Write to dpo@sociaro.com with what your procurement team needs.