Posture

What happens to your traffic.

We forward requests, meter them, and get out of the way. This sheet is the short version; SOC 2 Type II reports, DPAs, and architecture diagrams go out under mutual NDA.

SEC.01 — DATA HANDLING

Four promises that survive a subpoena.

Each of these is written into the customer agreement and the DPA, not just into this page. Where a promise is verifiable from your side, the response headers tell you how.

SEC 01.1

We don't train on your traffic

Prompts and completions routed through idclinktech are never used to train a model — ours, an upstream provider's, or anyone else's. Upstream agreements prohibit it, and the prohibition is audited rather than assumed.

SEC 01.2

We don't log content by default

A standard request writes metadata only: model ID, region, replica pool, token counts, latency, status. Prompt and completion bytes are not persisted. A content audit log exists, but it is opt-in per project and visible in the dashboard once enabled.

SEC 01.3

Zero-retention routes are first-class

Set X-IDC-No-Retention: true on any request and the gateway dispatches to a pool where prompt and completion bytes never leave volatile memory. No disk, no cache, no audit trail beyond the metering record.

SEC 01.4

Residency you can pin and verify

EU traffic stays in the EU; every other routed region is equally pinnable on Enterprise. The region and replica that served each call come back in X-IDC-* response headers, so the guarantee is checkable rather than trusted.

SEC.02 — COMPLIANCE FRAMEWORKS

What we hold ourselves to.

Framework Status Artifacts available
SOC 2 Type II In continuous audit Full report under NDA. The latest audit window covers Nov 2025 – Apr 2026; bridge letter on request.
GDPR / UK GDPR Compliant DPA with standard contractual clauses and the UK addendum, plus our record of processing activities.
CCPA / CPRA Compliant Documented subject-access request workflow. We do not sell or share personal information.
HIPAA BAA on request Available on Enterprise, paired with dedicated capacity and zero-retention routes.
ISO 27001 Target Q4 2026 Statement of applicability drafted; certificate published here on issuance, not before.

Regional data residency is contractual on Scale and above · verifiable per call in response headers

Nothing on this sheet is claimed as certified before the certificate exists

SEC.03 — OPERATING DISCIPLINE

The day-to-day, and its evidence.

Controls are only worth the artifact they leave behind. Each line below names the practice and the record a reviewer can ask for.

FIG.01 — DEFENSE IN SECTION

DEFENSE IN SECTION DWG IDC-DS-08 PERIMETER FACILITY CAGE RACK PROCESS VOLATILE MEMORY ONLY A A AUDIT TAP METADATA ONLY
Area Practice Evidence
Access Least privilege, reviewed quarterly. Production access is gated by hardware-backed SSO, privileged sessions are recorded, and reviewers rotate so no team approves itself. Customer content is never opened without a written ticket from the customer. Quarterly review log
Encryption In transit, at rest, service to service. TLS 1.3 on every external endpoint; mutual TLS with rotating certificates between internal services. Billing records, metadata, and audit logs are encrypted at rest under envelope keys held in an HSM. TLS 1.3 · HSM keys
Secrets Short-lived, auditable, rotatable. API keys are hashed at rest with a per-key salt and can be rotated from the dashboard or the management API. We never mail a key and never log one in full. Per-key salt · rotation API
Vulnerability Pressure-tested inside and out. Annual third-party penetration tests plus continuous internal red-team work against the gateway and management API. Public disclosure runs at security@idclinktech.com with same-business-day acknowledgment. Annual pentest summary
Resilience Multi-region, drilled quarterly. Each routed region is independently sufficient for global traffic at degraded capacity. A full region-failure drill runs every quarter and the recovery timeline is published to Scale and Enterprise customers. Quarterly drill report

SEC.04 — SUBPROCESSORS

Everyone else who touches a request.

Which upstream sees a request is decided entirely by the model ID you send. Closed-weight IDs resolve to their originating provider; open-weight IDs resolve to idclinktech managed pools. Subprocessor changes are notified 30 days in advance and the binding list lives in the DPA.

TABLE 04.1 — INFERENCE SUBPROCESSORS

Subprocessor Reached by Regions
OpenAIGPT model IDsUS, EU
AnthropicClaude model IDsUS, EU
GoogleGemini model IDsUS, EU, APAC
xAIGrok model IDsUS
DeepSeekDeepSeek model IDsAPAC
Alibaba CloudCommercial Qwen model IDsAPAC
Mistral AIMistral and Codestral commercial IDsEU
CohereCommand model IDsUS, CA
MicrosoftAzure-served model IDsUS, EU
Moonshot AIKimi model IDsAPAC
Zhipu AIGLM model IDsAPAC
MiniMaxMiniMax model IDsAPAC
Managed open-weight poolsOpen-weight IDs: Llama, open Qwen, open Mistral, Phi, Command weightsidclinktech-operated capacity · hosted rate appliesUS, EU

TABLE 04.2 — PLATFORM SUBPROCESSORS

Subprocessor Purpose Regions
Cloud infrastructureCompute, network, object storage for the gateway itselfUS, EU, APAC
Payment processorCard and ACH billing — full card numbers never reach usUS
Identity providerDashboard SSO and MFAUS
Email deliveryTransactional, billing, and incident notificationsUS

Open-weight pools are operated by idclinktech · no customer content is resold or brokered onward

Full retention and transfer terms are on the privacy sheet

SEC.05 — PROCUREMENT

Reviewing us
for procurement?

Send the questionnaire to sales@idclinktech.com. SOC 2 reports, DPAs, architecture diagrams, and penetration test summaries come back under mutual NDA. Vulnerability reports go to security@idclinktech.com.