We don't train on your traffic
Prompts and completions routed through idclinktech are never used to train a model — ours, an upstream provider's, or anyone else's. Upstream agreements prohibit it, and the prohibition is audited rather than assumed.
Posture
We forward requests, meter them, and get out of the way. This sheet is the short version; SOC 2 Type II reports, DPAs, and architecture diagrams go out under mutual NDA.
SEC.01 — DATA HANDLING
Each of these is written into the customer agreement and the DPA, not just into this page. Where a promise is verifiable from your side, the response headers tell you how.
Prompts and completions routed through idclinktech are never used to train a model — ours, an upstream provider's, or anyone else's. Upstream agreements prohibit it, and the prohibition is audited rather than assumed.
A standard request writes metadata only: model ID, region, replica pool, token counts, latency, status. Prompt and completion bytes are not persisted. A content audit log exists, but it is opt-in per project and visible in the dashboard once enabled.
Set X-IDC-No-Retention: true on any request and the gateway dispatches to a pool where prompt and completion bytes never leave volatile memory. No disk, no cache, no audit trail beyond the metering record.
EU traffic stays in the EU; every other routed region is equally pinnable on Enterprise. The region and replica that served each call come back in X-IDC-* response headers, so the guarantee is checkable rather than trusted.
SEC.02 — COMPLIANCE FRAMEWORKS
| Framework | Status | Artifacts available |
|---|---|---|
| SOC 2 Type II | In continuous audit | Full report under NDA. The latest audit window covers Nov 2025 – Apr 2026; bridge letter on request. |
| GDPR / UK GDPR | Compliant | DPA with standard contractual clauses and the UK addendum, plus our record of processing activities. |
| CCPA / CPRA | Compliant | Documented subject-access request workflow. We do not sell or share personal information. |
| HIPAA | BAA on request | Available on Enterprise, paired with dedicated capacity and zero-retention routes. |
| ISO 27001 | Target Q4 2026 | Statement of applicability drafted; certificate published here on issuance, not before. |
Regional data residency is contractual on Scale and above · verifiable per call in response headers
Nothing on this sheet is claimed as certified before the certificate exists
SEC.03 — OPERATING DISCIPLINE
Controls are only worth the artifact they leave behind. Each line below names the practice and the record a reviewer can ask for.
FIG.01 — DEFENSE IN SECTION
| Area | Practice | Evidence |
|---|---|---|
| Access | Least privilege, reviewed quarterly. Production access is gated by hardware-backed SSO, privileged sessions are recorded, and reviewers rotate so no team approves itself. Customer content is never opened without a written ticket from the customer. | Quarterly review log |
| Encryption | In transit, at rest, service to service. TLS 1.3 on every external endpoint; mutual TLS with rotating certificates between internal services. Billing records, metadata, and audit logs are encrypted at rest under envelope keys held in an HSM. | TLS 1.3 · HSM keys |
| Secrets | Short-lived, auditable, rotatable. API keys are hashed at rest with a per-key salt and can be rotated from the dashboard or the management API. We never mail a key and never log one in full. | Per-key salt · rotation API |
| Vulnerability | Pressure-tested inside and out. Annual third-party penetration tests plus continuous internal red-team work against the gateway and management API. Public disclosure runs at security@idclinktech.com with same-business-day acknowledgment. | Annual pentest summary |
| Resilience | Multi-region, drilled quarterly. Each routed region is independently sufficient for global traffic at degraded capacity. A full region-failure drill runs every quarter and the recovery timeline is published to Scale and Enterprise customers. | Quarterly drill report |
SEC.04 — SUBPROCESSORS
Which upstream sees a request is decided entirely by the model ID you send. Closed-weight IDs resolve to their originating provider; open-weight IDs resolve to idclinktech managed pools. Subprocessor changes are notified 30 days in advance and the binding list lives in the DPA.
TABLE 04.1 — INFERENCE SUBPROCESSORS
| Subprocessor | Reached by | Regions |
|---|---|---|
| OpenAI | GPT model IDs | US, EU |
| Anthropic | Claude model IDs | US, EU |
| Gemini model IDs | US, EU, APAC | |
| xAI | Grok model IDs | US |
| DeepSeek | DeepSeek model IDs | APAC |
| Alibaba Cloud | Commercial Qwen model IDs | APAC |
| Mistral AI | Mistral and Codestral commercial IDs | EU |
| Cohere | Command model IDs | US, CA |
| Microsoft | Azure-served model IDs | US, EU |
| Moonshot AI | Kimi model IDs | APAC |
| Zhipu AI | GLM model IDs | APAC |
| MiniMax | MiniMax model IDs | APAC |
| Managed open-weight pools | Open-weight IDs: Llama, open Qwen, open Mistral, Phi, Command weightsidclinktech-operated capacity · hosted rate applies | US, EU |
TABLE 04.2 — PLATFORM SUBPROCESSORS
| Subprocessor | Purpose | Regions |
|---|---|---|
| Cloud infrastructure | Compute, network, object storage for the gateway itself | US, EU, APAC |
| Payment processor | Card and ACH billing — full card numbers never reach us | US |
| Identity provider | Dashboard SSO and MFA | US |
| Email delivery | Transactional, billing, and incident notifications | US |
Open-weight pools are operated by idclinktech · no customer content is resold or brokered onward
Full retention and transfer terms are on the privacy sheet
SEC.05 — PROCUREMENT
Send the questionnaire to sales@idclinktech.com. SOC 2 reports, DPAs, architecture diagrams, and penetration test summaries come back under mutual NDA. Vulnerability reports go to security@idclinktech.com.