Security and privacy
Security and privacy require technical controls and transparency about how data is processed. These are Semantara's current controls and limitations.
Key encryption (AES-256-GCM)
Your provider keys are stored encrypted with AES-256-GCM. The encryption key is managed outside the database and never logged in plain text.
BYOK: you control your keys
You use your own keys for supported providers. We do not resell usage or interfere with billing from those providers; you can revoke access at any time.
Account isolation and cache scopes
Provider keys, configuration, and account metrics are logically isolated per client. Cache scope can be disabled, private-client, private-key, or public; the public scope uses a pool shared across clients and must not be used for personal, confidential, or secret data.
Key governance
Create, rotate, and deactivate service keys per client, controlling which providers and models each one can reach.
Data processing and retention
Semantara does not train its own models with your prompts or responses. To provide the service, content may be sent to the configured AI provider and to supporting classification or embedding services. request_logs does not store the raw prompt, but the cache may store prompts, responses, and embeddings. Formal retention periods and end-to-end deletion are still pending finalization.
Spend control and rate limits
Track your spend and savings in real time —cost is computed on every request, per client and per key— and set per-key rate limits to curb unexpected usage.
Infrastructure
The platform runs on managed cloud infrastructure, with secrets kept out of the code (loaded from the environment) and authenticated API access. For enterprise requirements, the Enterprise plan supports custom deployments.
Have specific compliance or security requirements? Contact us and we'll review them with you.
Contact us