Skip to content
INFRO

Trust

Security at INFRO

Routing your inference through a third party is a real trust decision. These are the commitments we make, stated plainly enough that you can hold us to them.

Your content is never training data
Prompts, inputs, and generated outputs are never used to train models — ours or anyone else's — and are never sold or shared beyond the route serving your request.
Zero-logging on demand
Set logging to false on any request and content is held in memory only for the life of that request. Metadata needed to bill you is still recorded; the payload is not written to disk.
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Provider credentials you attach for BYOK are sealed with AES-256-GCM, never logged, and never returned by the API after creation.
Scoped, revocable keys
Issue a key per service and per environment, each with its own spend ceiling. Revocation takes effect immediately, and rotation overlaps so it costs no downtime.
Regional control
Pin traffic to US, EU, or APAC routes when residency matters. Open-weight models are served from datacenters you choose rather than wherever is cheapest by default.
Isolation between tenants
Requests, job outputs, and stored assets are scoped to your account. Generated media is served over expiring signed URLs, not public buckets.

These are the controls INFRO is built to — and every one of them is testable. Ask for the report, the agreement, or the current subprocessor list and we will send it.

Certifications & agreements

SOC 2 Type IICertified
Independently audited controls for security, availability, and confidentiality. Report available under NDA.
ISO 27001Certified
Certified information-security management system covering the gateway, console, and supporting infrastructure.
GDPRAvailable
Data Processing Agreement with Standard Contractual Clauses, a published subprocessor list, and tooling for data-subject requests.
EU data residencyAvailable
Pin an organization or project to the EU routing zone and request content is processed only in EU datacenters.
EU AI ActAvailable
Per-request model provenance and retained logs that support Article 50 transparency and your record-keeping duties.
DPAAvailable
Standard data-processing agreement, reviewed and countersigned from the console — no email round-trips.

Working with procurement

Audit reports are shared under NDA from the console, the DPA is countersigned there in minutes, and the subprocessor list is public so you always know which routes can serve your traffic. If your process needs something we have not published, email hello@infro.io and we will tell you honestly whether we have it.

Reporting a vulnerability

Send findings to security@infro.io. We acknowledge reports within one business day, keep you updated while we investigate, and will not pursue legal action against good-faith research that avoids privacy violations, service degradation, and data destruction.

Related reading