Encrypted transport
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
Current product safeguards, data practices, and assurance status. Claims on this page are limited to what Phaseo can support today.
Use the detailed material for security review, vendor assessment, or DPA discussion.
Architecture, data flows, current safeguards, limitations, and customer responsibilities.
Self-attested
Core infrastructure, conditional processors, and customer-directed third parties.
Public schedule
A non-binding first draft for UK and EU controller-to-processor review.
Legal review required
Product and operational safeguards supported by current code and documentation.
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. API, management, and OAuth secrets use one-way HMAC or password-based derivation before storage.
Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.
SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.
Reports can be submitted through GitHub Security Advisories or [email protected]. Phaseo targets acknowledgement within three business days.
How gateway content is handled by default, where exceptions apply, and what remains provider-dependent.
Raw prompts and full outputs are excluded from Phaseo's primary request database and analytics. Eligible non-streaming outputs may be cached in Upstash for five minutes by default, and up to 24 hours when a cache policy is configured.
A feature-gated workspace setting can store request, response, and optional provider payloads in private Cloudflare R2 for 90, 180, or 365 days. It is off by default.
This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.
Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.
Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.
Categories disclosed in Phaseo's current privacy policy.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare and Vercel | Host, secure, and deliver the service | Service traffic, request content in transit, and operational metadata needed to run Phaseo |
| Supabase | Database and account infrastructure | Account, workspace, configuration, and request metadata |
| Upstash | Short-lived response caching | Cached model outputs, workspace-scoped cache keys, and response metadata |
| Stripe | Payments and billing | Billing identity and transaction records; Phaseo does not store full card details |
| Analytics and feature providers | Product analytics, feature delivery, and error diagnosis | Page, device, identity, and usage telemetry; raw gateway prompts and outputs are excluded |
| Email and support providers | Service communications and customer support | Contact details, message or ticket contents, and related account context |
| Model providers | Process the inference request you route | Inputs, outputs, and necessary request metadata; provider terms and retention apply |
| Connected assistant providers | Return authorised OAuth tool results | Only the read-only result and scopes approved through the consent flow |
See the dated subprocessor schedule for named vendors, conditions, location gaps, and the separate treatment of customer-selected AI providers.
Current health and incidents are published at status.phaseo.app. Phaseo does not claim a contractual public uptime SLA.
Operational code includes incident notification and outreach paths. Internal playbooks are not public, and the process has not been independently tested.
Phaseo does not currently hold an independent security certification. The public DPA is a non-binding first draft and the security whitepaper is self-attested. A formal assurance programme may be considered when customer need and budget justify it; no framework or date is committed.
Report security issues privately. Do not access other people's data, run denial-of-service tests, or disclose a vulnerability before a fix is available.