HostYourAI

Security & Compliance

How we handle your data, what we log, where it runs, and what we will sign for.

Last updated: 2026-06-10. This page is a public summary; the binding details live in our Data Processing Agreement and Terms.

Our promise in one paragraph

We run LLM inference on EU-located GPUs by default. Your prompts and responses are never used to train models, never logged in cleartext by default, and traffic is encrypted in transit. We sign Data Processing Agreements as a GDPR sub-processor, our sub-processor list is public, and you can compel deletion of your data at any time.

1. Data handling

What we process

What we do NOT do

2. Encryption

3. Where your data is processed

By default, inference runs on EU-region GPUs (currently Vast.ai EU machines for the EU Hosted beta). This means EU-located processing, not yet a fully EU-sovereign provider chain. Sovereignty Mode is sold only when a verified EU-sovereign provider path, sub-processor chain, audit export, and support-access controls are active for the customer. The default region is set per API key and overridable per request.

4. Logging & retention

WhatLogged?Retention (default)Configurable?
Prompt contentNo (by default)0 daysYes (opt-in transcripting)
Response contentNo (by default)0 daysYes (opt-in transcripting)
Request metadata (model, tokens, latency, IP, jurisdiction)Yes90 days30–365 days per contract
Audit log (key creation, deletions, admin actions)Yes (append-only)365 daysPer contract
Knowledge base documentsYes (encrypted, you upload them)Until you deleteOwner-controlled

5. Your rights — deletion & export

6. Sub-processors

The current list of sub-processors is published at /legal/subprocessors. We notify customers in advance of any sub-processor change and offer the right to object.

7. Isolation

8. Authentication & access control

9. Incident response

10. Certifications & roadmap

We will not falsely claim certifications we do not yet hold. If a certification is required for procurement, please ask — we can share our current state, the audit timeline, and compensating controls.

11. The DPA

Our standard Data Processing Agreement covers all of the above contractually. We will sign customer-supplied DPAs that materially match it; bespoke negotiations are welcome for enterprise contracts.

Get in touch

For security or compliance questions, contact security@hostyourai.com. For commercial questions including partner tiers, sub-processor approvals, or custom DPA terms, /contact.