PhaseoPhaseo
PhaseoPhaseo
Checking statusChecking statusVisit status page
Component-level status is unavailable.

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

© 2025 • Phaseo

Report:Issue·Support

Spotted a data issue or broken page?Open an issueorcontact support

PhaseoPhaseo
ModelsChatCompareProvidersAppsRankings
ModelsChatCompareProvidersAppsRankings
Phaseo Trust Centre

Security and trust at Phaseo

Current product safeguards, data practices, and assurance status. Claims on this page are limited to what Phaseo can support today.

Assurance
Self-attested
Last reviewed
30 August 2026
DocumentsSecurityData handlingService providersAvailabilityComplianceDisclosure

Claim labels

Available
In the product today.
Gated
Available only to eligible workspaces or configurations.
Self-attested
Described from Phaseo's own code, policy, and operations; not independently audited.
Planned
Intended work, with no delivery date promised.
Independently certified
Verified by an external certification body. Phaseo has none today.

Phaseo is not SOC 2 or ISO 27001 certified. Its security programme has not been independently audited.

Trust documents

Use the detailed material for security review, vendor assessment, or DPA discussion.

Security whitepaper

Architecture, data flows, current safeguards, limitations, and customer responsibilities.

Self-attested

Subprocessors

Core infrastructure, conditional processors, and customer-directed third parties.

Public schedule

Data Processing Addendum

A non-binding first draft for UK and EU controller-to-processor review.

Legal review required

Security

Product and operational safeguards supported by current code and documentation.

Encrypted transport

Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.

Self-attested

Provider key protection

Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. API, management, and OAuth secrets use one-way HMAC or password-based derivation before storage.

Self-attested

Scoped access and OAuth

Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.

Available

Enterprise identity

SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.

Gated

Private vulnerability reporting

Reports can be submitted through GitHub Security Advisories or [email protected]. Phaseo targets acknowledgement within three business days.

Available

Data handling

How gateway content is handled by default, where exceptions apply, and what remains provider-dependent.

Gateway content by default

Raw prompts and full outputs are excluded from Phaseo's primary request database and analytics. Eligible non-streaming outputs may be cached in Upstash for five minutes by default, and up to 24 hours when a cache policy is configured.

Self-attested

Private I/O logging

A feature-gated workspace setting can store request, response, and optional provider payloads in private Cloudflare R2 for 90, 180, or 365 days. It is off by default.

Gated

Optional data contribution

This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.

Available

Provider retention and training

Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.

Self-attested

Regional routing

Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.

Gated

Service providers

Categories disclosed in Phaseo's current privacy policy.

ProviderPurposeData involved
Cloudflare and VercelHost, secure, and deliver the serviceService traffic, request content in transit, and operational metadata needed to run Phaseo
SupabaseDatabase and account infrastructureAccount, workspace, configuration, and request metadata
UpstashShort-lived response cachingCached model outputs, workspace-scoped cache keys, and response metadata
StripePayments and billingBilling identity and transaction records; Phaseo does not store full card details
Analytics and feature providersProduct analytics, feature delivery, and error diagnosisPage, device, identity, and usage telemetry; raw gateway prompts and outputs are excluded
Email and support providersService communications and customer supportContact details, message or ticket contents, and related account context
Model providersProcess the inference request you routeInputs, outputs, and necessary request metadata; provider terms and retention apply
Connected assistant providersReturn authorised OAuth tool resultsOnly the read-only result and scopes approved through the consent flow

See the dated subprocessor schedule for named vendors, conditions, location gaps, and the separate treatment of customer-selected AI providers.

Availability and incidents

Service status

Current health and incidents are published at status.phaseo.app. Phaseo does not claim a contractual public uptime SLA.

Incident response

Operational code includes incident notification and outreach paths. Internal playbooks are not public, and the process has not been independently tested.

Compliance

Phaseo does not currently hold an independent security certification. The public DPA is a non-binding first draft and the security whitepaper is self-attested. A formal assurance programme may be considered when customer need and budget justify it; no framework or date is committed.

  • SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent Phaseo certification
  • A completed independent penetration test or published audit report
  • A contractual uptime SLA for the public service
  • Universal zero data retention or a guarantee that providers do not train on request data
  • Guaranteed regional data residency for every provider and route
  • A legal opinion or automatically executed DPA from the public first draft

Responsible disclosure

Report security issues privately. Do not access other people's data, run denial-of-service tests, or disclose a vulnerability before a fix is available.

Email securityPrivate GitHub report
Privacy PolicyTerms of ServiceContact
Reviewed against repository evidence
Sign Up