Trust

Built for teams that ship AI to production.

applayer is designed around a simple assumption: your customer data and your business processes are the most sensitive assets you own. Every model interaction runs through controls you can inspect, restrict, and audit.

Current controls

The controls we operate today.

This page is maintained by applayer.io to answer common security and privacy questions. It reflects controls currently enabled in the platform and is not an independent certification.

Access & authentication

SSO via SAML and OIDC. SCIM provisioning. Role-based access at the app, connector, and policy level.

Data handling

Zero-retention by default with our model providers. Customer data isolated per tenant. Fine-grained retention windows per data source.

Encryption

TLS 1.2+ in transit. AES-256 at rest. Optional customer-managed keys on enterprise deployments.

Audit & observability

Immutable audit logs for every prompt, tool call, and model response. Streamed to your SIEM on request.

Guardrails & policy

Deterministic policies, PII redaction, approval flows, and per-team spend caps enforced before the model is called.

Deployment options

Multi-tenant SaaS, single-tenant VPC, or bring-your-own AWS/Azure/GCP account. Data residency in US and EU.

Shared responsibility

Where applayer ends and your team begins.

applayer runs the platform, the model routing, the guardrail engine, and the audit plane. You own your data, the policies you configure, and the humans who approve sensitive actions. We publish reference policies you can adopt or customize.

Security contact

security@applayer.io

Vulnerability reports

Responsible disclosure

Please include reproduction steps and impact. We acknowledge within one business day.

Need our security package for procurement?

Reach out and we'll share the full document set under NDA.

Contact security