Security & compliance

DriftWatch sits directly in your inference path, so the security bar is the same one your provider has to clear. Here is exactly how traffic is handled.

Encrypted end to end

TLS 1.3 on every proxy hop and AES-256 at rest. Provider keys are forwarded upstream in-memory and never written to disk.

Zero training commitment

Prompts, completions and pruned payloads are never used to train models — ours or anyone else's.

Scoped, revocable keys

DriftWatch keys are hashed at rest, shown once, scoped per permission and revocable instantly from the dashboard.

Tenant isolation

Row-level security scopes every log, rule and key to its owner. Enterprise plans get a single-tenant proxy instance.

Audit & compliance

Built on SOC 2 Type II and ISO 27001 compliant cloud infrastructure with HIPAA-aligned logging, end-to-end payload encryption, and zero model-training commitments. Exportable audit trails on Growth and Enterprise.

Retention you control

Log retention runs 7 to 365 days by plan, with payload redaction rules and on-demand deletion.

Reporting a vulnerability

Email security@driftwatchproxy.com with reproduction steps. We acknowledge within one business day and keep you updated until the issue is closed.