Trust

Security

Last updated: 26 July 2026

How your prompt data is handled

We do not train models on your traffic, and we do not sell or share it. Prompts and completions are processed to serve the request, to compute the savings you are billed on, and to populate the logs in your own dashboard. Nothing else.

We act as a processor under Article 28 GDPR: we handle your content on your instruction only, and forwarding to a model provider happens because your configuration says so. A data processing agreement is available on request.

Encryption

  • Everything is served over HTTPS. The gateway and the website require TLS 1.2 or newer, plaintext connections are refused, and HTTP requests are redirected rather than answered.
  • Provider API keys and other stored credentials are encrypted at the field level with AES-256-GCM before they reach the database, and are never returned through the API or written to logs.
  • Traffic from the gateway onward to each model provider runs over the provider's own TLS endpoint.

Infrastructure and subprocessors

The gateway runs on servers of Hetzner Online GmbH in Germany. The website is hosted separately by Netlify, Inc. in the United States and holds no customer content.

Beyond that, the subprocessors that see request content are the model providers you route to, which you choose through your own configuration. The current list, including the model providers, is available on request at security@tok-net.de. We notify customers before adding a subprocessor that processes customer content.

Availability

We commit to 99.96% monthly availability of the gateway, excluding announced maintenance and upstream provider outages. This is a contractual SLA, not a marketing figure: the definition, how availability is measured, and the service credits you can claim if we miss it are set out in § 6 of our AGB.

There is no public status page yet. Customers affected by an incident are notified by email, and maintenance is announced at least 48 hours in advance where possible.

Reporting a vulnerability

Send findings to security@tok-net.de, ideally with steps to reproduce and the affected endpoint.

Contact

For security questionnaires, a data processing agreement or an architecture review, get in touch or write to security@tok-net.de. How we handle personal data is described in our Datenschutzerklärung.