Encrypted transport
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
Current product safeguards, data practices, and assurance status. Claims on this page are limited to what Phaseo can support today.
Product and operational safeguards supported by current code and documentation.
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. OAuth client secrets are stored as peppered SHA-256 hashes.
Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.
SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.
Reports can be submitted through GitHub Security Advisories or [email protected]. Phaseo targets acknowledgement within three business days.
How gateway content is handled by default, where exceptions apply, and what remains provider-dependent.
Raw prompt and full model-output text is not persistently stored in Phaseo's primary database or analytics tools. Content passes through transient processing buffers and the selected model provider.
This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.
Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.
Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.
Categories disclosed in Phaseo's current privacy policy.
| Provider | Purpose | Data involved |
|---|---|---|
| Hosting providers | Host and deliver the service | Service traffic and operational metadata needed to run Phaseo |
| Supabase | Database and account infrastructure | Account, workspace, configuration, and request metadata |
| Stripe | Payments and billing | Billing identity and transaction records; Phaseo does not store full card details |
| Analytics providers | Product analytics and error diagnosis | Page, device, and usage telemetry; configured to exclude raw gateway prompts and outputs |
| Email and support providers | Service communications and customer support | Contact details, message contents, and related account context |
| Model providers | Process the inference request you route | Inputs, outputs, and necessary request metadata; provider terms and retention apply |
| Connected assistant providers | Return authorised OAuth tool results | Only the read-only result and scopes approved through the consent flow |
This is a public summary, not a contractual subprocessor schedule. Model providers vary by route. See the Privacy Policy.
Current health and incidents are published at status.phaseo.app. Phaseo does not claim a contractual public uptime SLA.
Operational code includes incident notification and outreach paths. Internal playbooks are not public, and the process has not been independently tested.
Phaseo does not currently hold an independent security certification. A formal assurance programme may be considered when customer need and budget justify it; no framework or date is committed.
Report security issues privately. Do not access other people's data, run denial-of-service tests, or disclose a vulnerability before a fix is available.