Security
Last updated: September 2026
1. Transport Security
All API traffic is served over HTTPS with TLS. Plain HTTP requests are not accepted by the API. Certificates are rotated automatically before expiry.
2. API Keys
Every customer receives dedicated API keys. A key is displayed once at creation and is never shown again. Keys are delivered through secure channels only, are never accepted in URL parameters, and are masked in all logs.
3. Current Access Controls
Permissions are enforced per key: each key can be scoped to specific models and carries its own rate limits (requests per minute, tokens per minute and concurrency). Requests outside a key's scope are rejected. IP allowlists can be configured per agreement. Internal access is layered by role and business need, limited to authorized personnel, and granted to as few personnel as practicable.
4. Key Rotation
Keys can be rotated at any time on request. Rotation issues a new key first, lets you switch traffic over, and then blocks the old key - no downtime. If you suspect a key has been exposed, contact us and we will rotate it immediately.
5. Data Handling
Prompts, model inputs and outputs, knowledge-base files, tool-call results, conversation context, agent configurations and API business data are treated as customer Interaction Data. Staff may not freely inspect this data. Minimal access is permitted only under applicable law, a separate written agreement, a public-safety emergency, or when requested by the customer for support or troubleshooting. Metadata and exception logs may be processed as necessary for billing, security, abuse prevention, fraud prevention and service operations. Without your explicit authorization, we will not use Model API call data, Interaction Data or Usage Data to train, fine-tune or optimize general-purpose foundation models offered to unspecified users.
6. Security Incidents
Reports of security vulnerabilities or suspected incidents are acknowledged promptly and handled by the on-call engineering team. For confirmed incidents affecting customer data, we investigate, contain and notify affected customers according to applicable law and the timeframe agreed in the service agreement. Suspected credential exposure is treated as a priority: affected keys may be blocked first and investigated immediately. Service providers that process metadata, logs, tickets or support information are bound by our instructions, contractual confidentiality and security review.
7. Contact
Security reports: security@iteracompute.com