Security & Trust
Built for teams that answer to auditors.
odnoga is maintained by odnoga to answer the security, privacy and compliance questions your team actually gets asked. This page is app-owner content — not an independent certification.
Shared responsibility
Security is layered. Here is who owns what.
- • Physical datacenters
- • Network / DDoS
- • Database & auth uptime
- • Payments PCI scope
- • RLS + audit logs
- • Vault key handling
- • Anti-abuse + rate limits
- • DPA + sub-processor list
- • Bug reports triage
- • Choosing which vendors to route to
- • Workspace member access
- • End-user consent + your own DPA
- • Application-level authorization
Controls we enable today
Our data pledges
- Your prompts, requests, and responses are never sold.
- Your data is never used to train odnoga models. We do not train models.
- Zero-retention mode is available for regulated workloads — request bodies are dropped after routing.
- You can export or delete your data at any time from the workspace settings.
- Sub-processors are listed publicly and 30-day advance notice is given for changes.
Data residency, vendor by vendor
Residency is not something a gateway can invent. It only exists where the model vendor publishes an in-region endpoint. odnoga routes to that endpoint when it exists, records the region on every request, and charges the regional uplift only when the region was genuinely honoured. In strict mode a request that cannot be served in your region is rejected with residency_blocked rather than quietly routed elsewhere.
| Vendor | EU | How it works | Vendor doc |
|---|---|---|---|
| Mistral | Yes — api.eu.mistral.ai | Dedicated EU regional endpoint, processed in EU/EFTA data centres. Vendor charges a regional upcharge, which we pass through as the uplift. | View |
| xAI | Yes — eu-west-1.api.x.ai | Regional endpoint that fails the request rather than falling back to another region — exactly the behaviour strict residency needs. | View |
| OpenAI | Enterprise only — separate EU project required | OpenAI ties residency to the Project, set at creation for organisations approved for data residency. A standard key sent to eu.api.openai.com is rejected with 401 incorrect_hostname, so we do not offer it as a self-serve region. | View |
| Google (Gemini API) | No in-region endpoint on the direct API | Regional and EU multi-region processing exists on Vertex AI with a customer GCP project, not on the direct Gemini API keys a gateway holds. | View |
| Anthropic | No in-region endpoint on the direct API | Claude is served from a single global API surface; in-region options exist only through Bedrock or Vertex with your own cloud account. | View |
Where a vendor has no in-region endpoint, the request runs on that vendor’s global endpoint, the Models page labels it "global endpoint · no EU residency", and no regional uplift is billed.
EU regulation: what applies to odnoga
Certifications we inherit
odnoga runs on certified infrastructure. Those certifications belong to our sub-processors, not to odnoga. Our own SOC 2 Type I and ISO 27001 programmes are on the roadmap below.
| Provider | Attestations | Purpose | Trust page |
|---|---|---|---|
| Supabase | SOC 2 Type II, HIPAA | Database, auth, edge functions | View |
| Amazon Web Services | SOC 1/2/3, ISO 27001, PCI DSS L1, HIPAA, FedRAMP | Underlying cloud (via Supabase) | View |
| Stripe | PCI DSS Level 1, SOC 1/2, ISO 27001 | Payments, invoicing | View |
| Cloudflare | ISO 27001, SOC 2 Type II, PCI DSS | CDN, DDoS, Turnstile captcha | View |
| Twilio | SOC 2 Type II, ISO 27001, HIPAA | Phone verification (anti-abuse only) | View |
| Resend | SOC 2 Type II | Transactional email | View |
Compliance roadmap
External penetration test cadence: at least annually and after material architectural changes.
90-day disclosure window. No litigation for good-faith research within scope.
This page describes controls enabled today. It is not a certification and does not replace the DPA or an audit report. For contractual commitments, see the DPA and Terms of Service.