PhaseoPhaseo
PhaseoPhaseo
Checking statusChecking statusVisit status page
Component-level status is unavailable.

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

© 2025 • Phaseo

Report:Issue·Support

Spotted a data issue or broken page?Open an issueorcontact support

PhaseoPhaseo
ModelsChatCompareProvidersAppsRankings
ModelsChatCompareProvidersAppsRankings
Phaseo Trust Centre

Security and trust at Phaseo

Current product safeguards, data practices, and assurance status. Claims on this page are limited to what Phaseo can support today.

Assurance
Self-attested
Last reviewed
23 August 2026
SecurityData handlingService providersAvailabilityComplianceDisclosure

Claim labels

Available
In the product today.
Gated
Available only to eligible workspaces or configurations.
Self-attested
Described from Phaseo's own code, policy, and operations; not independently audited.
Planned
Intended work, with no delivery date promised.
Independently certified
Verified by an external certification body. Phaseo has none today.

Phaseo is not SOC 2 or ISO 27001 certified. Its security programme has not been independently audited.

Security

Product and operational safeguards supported by current code and documentation.

Encrypted transport

Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.

Self-attested

Provider key protection

Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. OAuth client secrets are stored as peppered SHA-256 hashes.

Self-attested

Scoped access and OAuth

Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.

Available

Enterprise identity

SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.

Gated

Private vulnerability reporting

Reports can be submitted through GitHub Security Advisories or [email protected]. Phaseo targets acknowledgement within three business days.

Available

Data handling

How gateway content is handled by default, where exceptions apply, and what remains provider-dependent.

Gateway content by default

Raw prompt and full model-output text is not persistently stored in Phaseo's primary database or analytics tools. Content passes through transient processing buffers and the selected model provider.

Self-attested

Optional data contribution

This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.

Available

Provider retention and training

Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.

Self-attested

Regional routing

Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.

Gated

Service providers

Categories disclosed in Phaseo's current privacy policy.

ProviderPurposeData involved
Hosting providersHost and deliver the serviceService traffic and operational metadata needed to run Phaseo
SupabaseDatabase and account infrastructureAccount, workspace, configuration, and request metadata
StripePayments and billingBilling identity and transaction records; Phaseo does not store full card details
Analytics providersProduct analytics and error diagnosisPage, device, and usage telemetry; configured to exclude raw gateway prompts and outputs
Email and support providersService communications and customer supportContact details, message contents, and related account context
Model providersProcess the inference request you routeInputs, outputs, and necessary request metadata; provider terms and retention apply
Connected assistant providersReturn authorised OAuth tool resultsOnly the read-only result and scopes approved through the consent flow

This is a public summary, not a contractual subprocessor schedule. Model providers vary by route. See the Privacy Policy.

Availability and incidents

Service status

Current health and incidents are published at status.phaseo.app. Phaseo does not claim a contractual public uptime SLA.

Incident response

Operational code includes incident notification and outreach paths. Internal playbooks are not public, and the process has not been independently tested.

Compliance

Phaseo does not currently hold an independent security certification. A formal assurance programme may be considered when customer need and budget justify it; no framework or date is committed.

  • SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent Phaseo certification
  • A completed independent penetration test or published audit report
  • A contractual uptime SLA for the public service
  • Universal zero data retention or a guarantee that providers do not train on request data
  • Guaranteed regional data residency for every provider and route
  • A downloadable DPA, security whitepaper, or compliance report

Responsible disclosure

Report security issues privately. Do not access other people's data, run denial-of-service tests, or disclose a vulnerability before a fix is available.

Email securityPrivate GitHub report
Privacy PolicyTerms of ServiceContact
Reviewed against repository evidence
Sign Up