Aliyun Bailian (Qwen + Wan) is now live — 13 models across two regions, routed to whichever side is cheaper for each model.Read more
Trust & Security

Security Built Into Every Request

Router AI is the infrastructure layer between your apps and AI providers. Every request passes through one consistent security boundary — AWS KMS envelope encryption, key isolation, audit logging, and access control built in, not bolted on.

What We Collect, Store, and Don't Store

Router AI is a middleman. Here's exactly what data we see at each layer, what gets persisted, and what doesn't.

Prompts & Responses

Not persisted by default Request and response bodies pass through our gateway for routing, but are not stored in our database. Only request metadata (model name, token counts, latency, status code) is retained for billing and analytics. Read data collection policy →

Request Metadata

Stored for 90 days (configurable) We store: timestamp, user ID, model ID, prompt tokens, completion tokens, total cost, latency, HTTP status, and error type (if failed). This enables usage accounting, billing reconciliation, and incident investigation. Data is automatically purged after the retention period (default 90 days, configurable per tenant from 1–730 days). See usage accounting →

Your API Keys

Hashed or KMS-encrypted, never logged Router AI API keys (sk-*) are stored as irreversible bcrypt hashes — they cannot be recovered even with database access. BYOK provider keys are protected with AWS KMS envelope encryption: each credential gets a unique data encryption key (DEK) generated by AWS Key Management Service, wrapped with a KMS master key, and the secret is encrypted with AES-256-GCM. Plaintext DEKs are zeroed from memory immediately after use. No key ever appears in application logs, metrics, or error traces. API key management →

Provider Credentials

Isolated in environment secrets Upstream provider API keys (for shared endpoints) are stored as Kubernetes Secrets or environment variables, never in the application database. Each provider runs in an isolated Pod with no cross-provider access. Model routing overview →
Not persisted by default Stored for 90 days (configurable) Hashed or KMS-encrypted, never logged Isolated in environment secrets

Request Lifecycle: What's Visible at Each Layer

A single request passes through multiple network boundaries. Here's what data is visible and persisted at each hop.

Prompt and completion bodies are never written to our database. They exist only in request/response memory during routing.

User Client Visible: Full request (headers, body, API key) Persisted: None (client-side only) → CloudFront Visible: TLS-encrypted traffic, HTTP headers Persisted: Access logs (IP, timestamp, status) — 7 days → Gateway Visible: Full request (routing, auth, billing) Persisted: Metadata only (tokens, cost, latency) — 90 days → Provider Pod Visible: Transformed request for upstream API Persisted: None (stateless, logs only transient errors) → Upstream API Visible: Full request sent to OpenAI/Anthropic/etc Persisted: Provider-dependent (see provider privacy policies)

Architecture Security: Design Decisions That Matter

Security isn't just encryption—it's isolation, redundancy, and blast radius containment built into the infrastructure layer.

Provider Isolation

Each upstream provider (OpenAI, Anthropic, Bedrock, etc.) runs as a separate Kubernetes Pod. A vulnerability in one provider adapter cannot access credentials or request data from another. No shared process memory, no lateral movement. Why it matters: Limits blast radius if a provider adapter is compromised

CloudFront as API Gateway

All requests hit AWS CloudFront before reaching our origin. This provides DDoS mitigation (AWS Shield Standard), TLS termination, WAF protection, and GeoIP-based request metadata. CloudFront's global edge network absorbs volumetric attacks before they reach our infrastructure. Why it matters: Protects against volumetric DDoS, common attack patterns, and certificate management errors

Multi-Region Separation

Global traffic routes through AWS (us-east-2). China-based model providers (Qwen, Doubao, Zhipu, DeepSeek) are reached via their native endpoints — data-sovereignty-sensitive workloads can pin routing to in-region providers. Why it matters: Ensures compliance with data sovereignty requirements

Payment Data Isolation

Router AI does not store credit card numbers, CVV, or bank account details. Payment processing is handled by Stripe via a dedicated payment service. Only payment method IDs and transaction receipts are stored in our database. Why it matters: Removes PCI-DSS compliance burden and minimizes payment fraud risk
Why it matters: Limits blast radius if a provider adapter is compromised Why it matters: Protects against volumetric DDoS, common attack patterns, and certificate management errors Why it matters: Ensures compliance with data sovereignty requirements Why it matters: Removes PCI-DSS compliance burden and minimizes payment fraud risk

Threat Model: What Could Go Wrong, and How We Mitigate It

No system is perfectly secure. Here's our assessment of realistic attack scenarios, their impact, and architectural mitigations.

Internal Threat (Malicious Insider)

Impact An employee with database access could read request metadata (model, tokens, cost, timestamps), encrypted API keys, and user emails. Prompt/response bodies are not in the database. Mitigation Database access restricted to application subnet via security group rules (RDS not publicly accessible). Customer API keys stored as irreversible bcrypt hashes; BYOK provider keys protected with AWS KMS envelope encryption — each credential encrypted with a unique data key (DEK) generated by KMS, wrapped by a hardware-backed master key. Even with full database access, encrypted credentials cannot be decrypted without KMS access and the correct tenant-scoped encryption context. DEKs are zeroed from memory after each use. Write operations via admin API logged to an audit trail with KMS operation events. Production infrastructure access limited to founding engineers.

External Breach (Database Compromise)

Impact If an attacker dumps the entire database, they get KMS-wrapped encrypted data keys and AES-256-GCM ciphertext (useless without AWS KMS access and correct encryption context), request metadata, and user account info. No plaintext prompts, responses, or API keys. Mitigation BYOK credentials use AWS KMS envelope encryption — the database stores only encrypted data keys and ciphertext. Decryption requires both AWS KMS API access and tenant-specific encryption context (tenantId + provider + purpose). A database dump alone reveals nothing. KMS master key protected by FIPS 140-2 Level 2 HSMs with deletion protection enabled. Database backups encrypted at rest with 14-day retention. CloudFront + WAF blocks common attack patterns.

Service Outage (Infrastructure Failure)

Impact If Router AI gateway goes down, all requests fail. Customers lose routing, failover, and billing visibility until service is restored. No data loss (database persists), but active requests return 503. Mitigation Multi-AZ RDS deployment with automated daily backups (14-day retention) and point-in-time recovery. EC2 auto-recovery alarms for instance failures. Provider fallback routing across multiple upstream APIs. Route 53 health checks with automated reboot on unresponsiveness. SLA commitments for incident response (see below).
Impact Mitigation Impact Mitigation Impact Mitigation

Security Incident Response SLA

These are target response times, not contractual guarantees. We commit to transparent communication during incidents, with acknowledgment and resolution timelines based on severity.

Targets, not guarantees. Actual response times may vary based on incident complexity and available resources.

Severity                Examples                Acknowledgment          Resolution Target       
Critical                API key leak, data breach, production authentication bypass24 hours                7 days                  
High                    Security vulnerability (RCE, SQL injection), TLS certificate expiry48 hours                30 days                 
Medium                  Non-critical security issue (XSS in docs, rate limit bypass)72 hours                90 days                 
Low                     Security suggestion, documentation improvement, feature request1 week                  Best effort             
Severity Examples Acknowledgment Resolution Target Critical API key leak, data breach, production authentication bypass 24 hours 7 days High Security vulnerability (RCE, SQL injection), TLS certificate expiry 48 hours 30 days Medium Non-critical security issue (XSS in docs, rate limit bypass) 72 hours 90 days Low Security suggestion, documentation improvement, feature request 1 week Best effort

Security FAQ

Common questions about data handling, encryption, compliance, and operational security.

Do you store my prompts and model responses?

How are my API keys protected? Is data separated between China and global regions? Do you use my data for model training or AI development? What happens if Router AI goes down? Do you have SOC 2 or ISO 27001 certification? Can I get a BAA (Business Associate Agreement) for HIPAA compliance? Not at this time. Router AI is not currently HIPAA-compliant and does not sign BAAs. If you handle protected health information (PHI), you should not route it through Router AI until we complete HIPAA certification. HIPAA compliance is planned for a future milestone, but we do not have a firm timeline yet. Contact us if this is a blocker for your use case.

Report a Security Issue

Found a vulnerability? Have a security concern? We take all reports seriously and respond according to the SLA commitments above.

Send email to security@routerai.lol

Include: vulnerability description, reproduction steps, impact assessment.

We acknowledge within 24-48 hours

Initial response confirms receipt and assigns a severity level.

We investigate and patch

Critical issues patched within 7 days, High within 30 days. You'll receive status updates.
Security contact
Trust & Security Security Built Into Every Request Router AI is the infrastructure layer between your apps and AI providers. Every request passes through one consistent security boundary — AWS KMS envelope encryption, key isolation, audit logging, and access control built in, not bolted on. Your BYOK credentials are encrypted at rest with AWS KMS hardware-backed keys. We document what we collect, where it goes, and who can see it. Engineering decisions made explicit, not hidden behind compliance logos. What We Collect, Store, and Don't Store Router AI is a middleman. Here's exactly what data we see at each layer, what gets persisted, and what doesn't. Prompts & Responses Not persisted by default Request and response bodies pass through our gateway for routing, but are not stored in our database. Only request metadata (model name, token counts, latency, status code) is retained for billing and analytics. Read data collection policy → Request Metadata Stored for 90 days (configurable) We store: timestamp, user ID, model ID, prompt tokens, completion tokens, total cost, latency, HTTP status, and error type (if failed). This enables usage accounting, billing reconciliation, and incident investigation. Data is automatically purged after the retention period (default 90 days, configurable per tenant from 1–730 days). See usage accounting → Your API Keys Hashed or KMS-encrypted, never logged Router AI API keys (sk-*) are stored as irreversible bcrypt hashes — they cannot be recovered even with database access. BYOK provider keys are protected with AWS KMS envelope encryption: each credential gets a unique data encryption key (DEK) generated by AWS Key Management Service, wrapped with a KMS master key, and the secret is encrypted with AES-256-GCM. Plaintext DEKs are zeroed from memory immediately after use. No key ever appears in application logs, metrics, or error traces. API key management → Provider Credentials Isolated in environment secrets Upstream provider API keys (for shared endpoints) are stored as Kubernetes Secrets or environment variables, never in the application database. Each provider runs in an isolated Pod with no cross-provider access. Model routing overview → Request Lifecycle: What's Visible at Each Layer A single request passes through multiple network boundaries. Here's what data is visible and persisted at each hop. User Client Visible: Full request (headers, body, API key) Persisted: None (client-side only) CloudFront Visible: TLS-encrypted traffic, HTTP headers Persisted: Access logs (IP, timestamp, status) — 7 days Gateway Visible: Full request (routing, auth, billing) Persisted: Metadata only (tokens, cost, latency) — 90 days Provider Pod Visible: Transformed request for upstream API Persisted: None (stateless, logs only transient errors) Upstream API Visible: Full request sent to OpenAI/Anthropic/etc Persisted: Provider-dependent (see provider privacy policies) Prompt and completion bodies are never written to our database. They exist only in request/response memory during routing. Architecture Security: Design Decisions That Matter Security isn't just encryption—it's isolation, redundancy, and blast radius containment built into the infrastructure layer. Provider Isolation Each upstream provider (OpenAI, Anthropic, Bedrock, etc.) runs as a separate Kubernetes Pod. A vulnerability in one provider adapter cannot access credentials or request data from another. No shared process memory, no lateral movement. Why it matters: Limits blast radius if a provider adapter is compromised CloudFront as API Gateway All requests hit AWS CloudFront before reaching our origin. This provides DDoS mitigation (AWS Shield Standard), TLS termination, WAF protection, and GeoIP-based request metadata. CloudFront's global edge network absorbs volumetric attacks before they reach our infrastructure. Why it matters: Protects against volumetric DDoS, common attack patterns, and certificate management errors Multi-Region Separation Global traffic routes through AWS (us-east-2). China-based model providers (Qwen, Doubao, Zhipu, DeepSeek) are reached via their native endpoints — data-sovereignty-sensitive workloads can pin routing to in-region providers. Why it matters: Ensures compliance with data sovereignty requirements Payment Data Isolation Router AI does not store credit card numbers, CVV, or bank account details. Payment processing is handled by Stripe via a dedicated payment service. Only payment method IDs and transaction receipts are stored in our database. Why it matters: Removes PCI-DSS compliance burden and minimizes payment fraud risk Threat Model: What Could Go Wrong, and How We Mitigate It No system is perfectly secure. Here's our assessment of realistic attack scenarios, their impact, and architectural mitigations. Internal Threat (Malicious Insider) Impact An employee with database access could read request metadata (model, tokens, cost, timestamps), encrypted API keys, and user emails. Prompt/response bodies are not in the database. Mitigation Database access restricted to application subnet via security group rules (RDS not publicly accessible). Customer API keys stored as irreversible bcrypt hashes; BYOK provider keys protected with AWS KMS envelope encryption — each credential encrypted with a unique data key (DEK) generated by KMS, wrapped by a hardware-backed master key. Even with full database access, encrypted credentials cannot be decrypted without KMS access and the correct tenant-scoped encryption context. DEKs are zeroed from memory after each use. Write operations via admin API logged to an audit trail with KMS operation events. Production infrastructure access limited to founding engineers. External Breach (Database Compromise) Impact If an attacker dumps the entire database, they get KMS-wrapped encrypted data keys and AES-256-GCM ciphertext (useless without AWS KMS access and correct encryption context), request metadata, and user account info. No plaintext prompts, responses, or API keys. Mitigation BYOK credentials use AWS KMS envelope encryption — the database stores only encrypted data keys and ciphertext. Decryption requires both AWS KMS API access and tenant-specific encryption context (tenantId + provider + purpose). A database dump alone reveals nothing. KMS master key protected by FIPS 140-2 Level 2 HSMs with deletion protection enabled. Database backups encrypted at rest with 14-day retention. CloudFront + WAF blocks common attack patterns. Service Outage (Infrastructure Failure) Impact If Router AI gateway goes down, all requests fail. Customers lose routing, failover, and billing visibility until service is restored. No data loss (database persists), but active requests return 503. Mitigation Multi-AZ RDS deployment with automated daily backups (14-day retention) and point-in-time recovery. EC2 auto-recovery alarms for instance failures. Provider fallback routing across multiple upstream APIs. Route 53 health checks with automated reboot on unresponsiveness. SLA commitments for incident response (see below). Security Incident Response SLA These are target response times, not contractual guarantees. We commit to transparent communication during incidents, with acknowledgment and resolution timelines based on severity. Severity Examples Acknowledgment Resolution Target Critical API key leak, data breach, production authentication bypass 24 hours 7 days High Security vulnerability (RCE, SQL injection), TLS certificate expiry 48 hours 30 days Medium Non-critical security issue (XSS in docs, rate limit bypass) 72 hours 90 days Low Security suggestion, documentation improvement, feature request 1 week Best effort Targets, not guarantees. Actual response times may vary based on incident complexity and available resources. Security FAQ Common questions about data handling, encryption, compliance, and operational security. Do you store my prompts and model responses? How are my API keys protected? Is data separated between China and global regions? Do you use my data for model training or AI development? What happens if Router AI goes down? Do you have SOC 2 or ISO 27001 certification? Can I get a BAA (Business Associate Agreement) for HIPAA compliance? Not at this time. Router AI is not currently HIPAA-compliant and does not sign BAAs. If you handle protected health information (PHI), you should not route it through Router AI until we complete HIPAA certification. HIPAA compliance is planned for a future milestone, but we do not have a firm timeline yet. Contact us if this is a blocker for your use case. Report a Security Issue Found a vulnerability? Have a security concern? We take all reports seriously and respond according to the SLA commitments above. Security contact security@routerai.lol Send email to security@routerai.lol Include: vulnerability description, reproduction steps, impact assessment. We acknowledge within 24-48 hours Initial response confirms receipt and assigns a severity level. We investigate and patch Critical issues patched within 7 days, High within 30 days. You'll receive status updates. Email security team We will not pursue legal action against good-faith security research. Last updated: March 29, 2026

Security FAQ

Do you store my prompts and model responses?

No, by default. Prompt and response bodies pass through our gateway for routing but are not written to our database. We only persist request metadata: model ID, token counts, cost, latency, and HTTP status code. This metadata enables billing, analytics, and incident investigation. If you enable request logging (opt-in feature, not yet available), we may store truncated request/response samples for debugging. This will be clearly documented when the feature ships.

How are my API keys protected?

Router AI API keys (sk-*) are stored as irreversible bcrypt hashes — they cannot be recovered even with full database access. BYOK provider keys are protected with AWS KMS envelope encryption: each credential is encrypted with a unique data encryption key (DEK) generated by AWS Key Management Service, wrapped by a hardware-backed master key (FIPS 140-2 Level 2 HSM). The actual encryption uses AES-256-GCM. Decryption requires both KMS API access and a tenant-specific encryption context (tenantId + provider + purpose) — a database dump alone reveals nothing. No key ever appears in application logs, error traces, or metrics. Plaintext DEKs are zeroed from memory immediately after each cryptographic operation.

Is data separated between China and global regions?

Yes. Global traffic now routes through AWS us-east-2. The legacy China endpoint has been retired for new integrations. Historical regional infrastructure remains isolated where applicable: Its own database (no cross-region queries) Its own Kubernetes cluster Its own provider credentials Its own domain and TLS certificate Regional data stores and credentials are not merged across environments. New integrations should use the global endpoint.

Do you use my data for model training or AI development?

No. Router AI does not train models or use your request data for any AI development. We are a routing and billing infrastructure layer, not a model provider. Your prompts and responses go directly to upstream providers (OpenAI, Anthropic, etc.). Their data usage policies apply—refer to each provider's terms of service for details on how they handle your data.

What happens if Router AI goes down?

If our gateway becomes unavailable, all requests return 503 until service is restored. Active requests fail immediately (no retry on our side). Your application should implement retry logic with exponential backoff. No data is lost—our database persists through outages. Request metadata already recorded remains intact. Once the gateway recovers, new requests resume normally. Mitigation: We use multi-AZ RDS, auto-scaling Gateway pods, and real-time monitoring. For critical workloads, configure provider fallback routes (if available in your plan).

Do you have SOC 2 or ISO 27001 certification?

SOC 2 Type II is in our roadmap. In the meantime, this page documents our actual security controls with the same level of specificity a SOC 2 audit would require — you can review the architecture, threat model, and incident response process directly. We do not claim compliance we haven't achieved. If SOC 2 is a hard requirement for your organization, please contact us to discuss timeline — your interest helps us prioritize the audit.

Can I get a BAA (Business Associate Agreement) for HIPAA compliance?

Not at this time. Router AI is not currently HIPAA-compliant and does not sign BAAs. If you handle protected health information (PHI), you should not route it through Router AI until we complete HIPAA certification. HIPAA compliance is planned for a future milestone, but we do not have a firm timeline yet. Contact us if this is a blocker for your use case.

AI API Security: Data Handling & Architecture | Router AI