Built for teams that ship AI to production.
applayer is designed around a simple assumption: your customer data and your business processes are the most sensitive assets you own. Every model interaction runs through controls you can inspect, restrict, and audit.
The controls we operate today.
This page is maintained by applayer.io to answer common security and privacy questions. It reflects controls currently enabled in the platform and is not an independent certification.
Access & authentication
SSO via SAML and OIDC. SCIM provisioning. Role-based access at the app, connector, and policy level.
Data handling
Zero-retention by default with our model providers. Customer data isolated per tenant. Fine-grained retention windows per data source.
Encryption
TLS 1.2+ in transit. AES-256 at rest. Optional customer-managed keys on enterprise deployments.
Audit & observability
Immutable audit logs for every prompt, tool call, and model response. Streamed to your SIEM on request.
Guardrails & policy
Deterministic policies, PII redaction, approval flows, and per-team spend caps enforced before the model is called.
Deployment options
Multi-tenant SaaS, single-tenant VPC, or bring-your-own AWS/Azure/GCP account. Data residency in US and EU.
Where applayer ends and your team begins.
applayer runs the platform, the model routing, the guardrail engine, and the audit plane. You own your data, the policies you configure, and the humans who approve sensitive actions. We publish reference policies you can adopt or customize.
Security contact
security@applayer.ioVulnerability reports
Responsible disclosurePlease include reproduction steps and impact. We acknowledge within one business day.
Need our security package for procurement?
Reach out and we'll share the full document set under NDA.
Contact security