Placeholder. Read before publishing.
Every certification, audit, and policy on this page is example content. Replace or delete all of it before you publish. Publishing a SOC 2, ISO 27001, or HIPAA claim you have not earned is fraud, and it is exactly the kind of claim enterprise buyers verify. If you have not completed an audit, delete the badge. An honest security page with three real facts converts better than a false one with ten.

Trust Center
Written to be read, not to survive a questionnaire.
Most security pages are compliance theatre. This one tells you what we hold, for how long, and who else touches it. If anything here is unclear, that is a bug. Tell us and we will rewrite it.

We do not train on your data.
Your prompts, completions, files, and eval sets are never used to train a model. Not by Plinth, and not by any provider we route to. A prohibition on training is a condition of being in our routing pool, and we re-verify it annually.
This is a contractual commitment rather than a setting. It applies on every plan, including free.
Certifications
What we have been audited against.
PLACEHOLDER
SOC 2 Type II
Audited annually by an independent firm. Report available under NDA.
PLACEHOLDER
ISO/IEC 27001
Certified, with annual surveillance audits.
PLACEHOLDER
GDPR
DPA available. Standard Contractual Clauses in place for transfers out of the EEA.
PLACEHOLDER
HIPAA
BAA available on Enterprise. Not available on self-serve plans.
PLACEHOLDER
CCPA
We do not sell personal information, and we never have.
Replace or remove before publishing.
Retention
What we keep, and for how long.
Zero is a valid answer, and it is the one most teams should pick.
Setting
What we keep
Available on
Zero-day
Nothing. Metadata only: model, token counts, latency, cost.
Pro and above
7 days
Request and response content, then deleted.
All plans, default on Free
30 / 90 days
Content retained for replay and eval promotion.
Pro, Scale
Custom
Set per project, down to zero.
Enterprise
Deletion means deletion. Backups roll off within 35 days and we will confirm in writing on request.
Sub-processors
Everyone else who touches it.
We use five vendors. Changes are announced 30 days in advance and you can subscribe to the notice.
Vendor
Purpose
Data
Region
Aurora Cloud
Compute and storage
Request content, metadata
US, EU
Beacon Telemetry
Application metrics
Metadata only
US
Pallas Payments
Billing
Name, email, billing address
US
Relay Mail
Transactional email
Name, email
US
Fathom Errors
Error reporting
Stack traces, metadata
EU
Placeholder. Replace with your actual vendors.
Controls
The rest of what your security team will ask.
Data residency
Pin processing to US or EU on Pro and above. Enterprise pins to a single region, traces and backups included.
Access controls
SSO and SAML on Scale. Role-based access on every plan. Production data access requires approval and is logged, and the log is available to you on request.
Encryption
TLS 1.3 in transit, AES-256 at rest. Keys rotate annually and on staff departure.
Incident response
We notify affected customers within 24 hours of confirming an incident, before we have finished investigating it. Post-mortems are published in full.
Vulnerability disclosure
Report to security@plinth.dev. We respond within one business day and never pursue good-faith researchers.
Availability
99.98% over the trailing 90 days. Historical uptime and every incident are on the status page.
Questionnaires
Send yours to security@plinth.dev. Most come back inside three business days. Our completed CAIQ is available under NDA.

Something missing?
If your security team needs a document that is not here, ask for it. We would rather write it once than answer it fifty times.