Open models, under
your own controls
The same API your developers already use, with the identity, data-handling and accountability terms your security review asks for. Nothing about the integration changes.
One business day, from a named engineer.
Off by default; when switched on, chosen per project.
Billing and engineering separable.
Searchable and exportable.
What the enterprise agreement adds
Every item below is a contract term or a setting your administrators control, not a marketing line. Each one is negotiated during scoping.
Reserved GPUs for the models that carry steady load, with no shared rate limits and a latency profile you can hold to.
Fine-tuned checkpoints and LoRA adapters imported from a model repository or your object storage, served on your own endpoints.
Connect your identity provider, require SSO for the organization, and provision members on first login with a default role.
Every administrative action and every access to your data, with actor, IP and time. Searchable, exportable, retained one year.
Prompts and outputs are never written to storage. Enforced organization-wide, and content logging cannot be switched on.
Constrain a project to specific regions, or to routes set aside for you by contract. A request that cannot satisfy the constraint fails instead of leaking out.
An uptime commitment with credits, a shared channel, and named engineers who already know your routing configuration.
Pay by bank transfer: sales books it to your balance as contract credit, under your contract or transfer reference, and your rate-limit tier can be set by the contract. Monthly statements carry your company name and tax ID. Billing is prepaid; invoices and postpaid terms are not offered yet.
Six roles, one organization
A member holds exactly one organization role. Billing and engineering are separable, which is usually the first thing a security review checks.
| Role | API keys | Spending | Members |
|---|---|---|---|
| Owner | Full | Full | Full |
| Admin | Full | View | Partial |
| Developer | Own keys | View | No |
| Billing Admin | No | Full | No |
| Viewer | No | Balance only | No |
| Auditor | No | View | Audit log |
Admin can remove developers, billing admins, viewers and auditors, but not another admin or the owner. Transferring ownership requires the current owner.
Where your prompts go
Request metadata is always recorded because billing and debugging depend on it. Prompt and output content is a separate decision, made per project.
| Mode | Metadata | Prompt and output | Retention |
|---|---|---|---|
| Default | Recorded | Not stored | 90 days |
| Content logging | Recorded | Stored, admin opt-in | 1 to 30 days, set per project |
| Zero data retention | Recorded | Never stored | Billing records only |
We never use customer content to train models — that is in the terms, not a setting. Zero data retention keeps your traffic on routes that are committed not to retain it.
TLS in transit and encryption at rest. API keys are stored as hashes and shown once; an encrypted copy is kept only if your organisation opts in, and every read of it is audited.
The subprocessor list, with each one's role and location, comes with your data processing addendum. You get thirty days' notice of changes and can object.
How an enterprise engagement runs
- 01/Scoping call
Which models, what volume, which regions, and what your security review needs. Usually thirty minutes, and we reply within one business day.
- 02/Proof of concept
Trial credit, a dedicated endpoint if latency matters, and hands-on help migrating one service so you measure against real traffic.
- 03/Agreement
SLA, data processing agreement, security questionnaire and pricing. Region, retention and subprocessor terms are settled here.
- 04/Onboarding
SSO connected, roles and budgets set, audit export configured, and a shared channel with the engineers who know your setup.
Start with the scoping call
Tell us what you run today and what your review needs. You will get a written answer on regions, retention and pricing before any call is scheduled.
- A written answer, not a discovery questionnaire
- Security review material sent up front
- Trial credit before any commitment
Common questions
Bring your security review
Name the questionnaire or framework your review uses in your first message, and we will send the material. Answering it is the fastest way to find out whether this fits.