Security practices and data handling
Summary: Your data is never stored. All traffic is encrypted. We don't train on your inputs. Enterprise DPA available on request.
SafetyGates is designed for privacy by default:
For service operation and billing:
All API traffic uses TLS 1.3 via Cloudflare. No unencrypted connections accepted.
Cloudflare's global network provides automatic DDoS mitigation on all plans.
API servers are not directly internet-accessible. All traffic routes through Cloudflare Tunnel.
Built-in rate limiting prevents abuse and ensures fair usage.
We monitor API uptime 24/7 with automated health checks. View real-time and historical status:
Paid tier API responses include a cryptographic watermark that allows us to trace leaked responses back to their source and detect unauthorized redistribution. Watermarks do not contain your API key or any personally identifiable information.
We follow industry security best practices. SOC 2 certification is on our roadmap. In the meantime, we're happy to complete security questionnaires and provide documentation of our practices.
SafetyGates complies with U.S. export control laws. Service is not available to embargoed countries or sanctioned entities. See our Terms of Service for details.
If you discover a security vulnerability, please report it responsibly:
No. Input text is processed in memory and immediately discarded.
No. We will never use customer input data for training without explicit written consent.
Yes. Enterprise customers can request a Data Processing Agreement at [email protected].
Not yet. We follow SOC 2 principles and plan to pursue certification. We're happy to answer security questionnaires in the meantime.
Security: [email protected]
Legal/Compliance: [email protected]
General: [email protected]
Last updated: January 11, 2026