Security & compliance
DriftWatch sits directly in your inference path, so the security bar is the same one your provider has to clear. Here is exactly how traffic is handled.
Encrypted end to end
TLS 1.3 on every proxy hop and AES-256 at rest. Provider keys are forwarded upstream in-memory and never written to disk.
Zero training commitment
Prompts, completions and pruned payloads are never used to train models — ours or anyone else's.
Scoped, revocable keys
DriftWatch keys are hashed at rest, shown once, scoped per permission and revocable instantly from the dashboard.
Tenant isolation
Row-level security scopes every log, rule and key to its owner. Enterprise plans get a single-tenant proxy instance.
Audit & compliance
Built on SOC 2 Type II and ISO 27001 compliant cloud infrastructure with HIPAA-aligned logging, end-to-end payload encryption, and zero model-training commitments. Exportable audit trails on Growth and Enterprise.
Retention you control
Log retention runs 7 to 365 days by plan, with payload redaction rules and on-demand deletion.
Reporting a vulnerability
Email security@driftwatchproxy.com with reproduction steps. We acknowledge within one business day and keep you updated until the issue is closed.