Skip to content
TokenShunt
Trust Center

Your code, your rules.

Routing touches your source code, so it has to follow your rules. You decide which models may see which repositories, every routed request is logged, and nothing is used for training.

Our commitments

Four promises in every contract.

These are not aspirations. They are written into our engagement terms and verifiable in your own logs.

  1. 01

    Your code is never used for training

    Nothing we see is used to train or improve any model, ours or anyone else's.

  2. 02

    Your rules on where code goes

    Routing policies decide which models may see which code. Sensitive repositories can stay on self-hosted models.

  3. 03

    Every routed change is logged

    Each request records which model handled it and why, exportable to your SIEM.

  4. 04

    Deploy where you need it

    Your cloud account, your data center, or a fully isolated network.

Certifications & audits

Independent assurance.

We are building our compliance program alongside our first engagements. Contact our security team for current policies, architecture documentation, and roadmap.

Data isolation guarantees

Your code never leaves your control.

  1. 01

    Your code stays where your policy says

    Routing policies decide which models may see which repositories. Sensitive code can be pinned to self-hosted models that never leave your network.

  2. 02

    Never used for training

    Your code, prompts, and outputs are never used to train, evaluate, or improve models for anyone else or for our own products.

  3. 03

    Dedicated infrastructure

    Routing and worker models run in infrastructure dedicated to you. Nothing is shared or commingled across clients.

  4. 04

    You own the configuration

    Routing rules, quality gates, and runbooks are delivered to and owned by you.

  5. 05

    Encryption in transit and at rest

    TLS 1.2+ in transit and AES-256 at rest, with customer-managed keys wherever your platform supports them.

  6. 06

    Verified deletion

    At engagement close, any working copies of usage data are destroyed and deletion is confirmed to you in writing.

Deployment options

Wherever your code is allowed to be.

The same routing and verification runs in every environment — so security requirements never force a compromise on savings.

Your cloud account

Data location
Your AWS, Azure, or GCP account
Network egress
Your policies
Operated by
You; we operate with delegated access

Typical for: Most cloud-first teams

Hybrid

Data location
Routing in your cloud, some jobs on approved APIs
Network egress
Only the jobs your policy allows
Operated by
You, with us

Typical for: Mixed-sensitivity codebases

On-premises

Data location
Your data center
Network egress
None required
Operated by
Your infrastructure team, with us

Typical for: Code that can't leave the building

Isolated network

Data location
Physically isolated network
Network egress
None — verified offline transfer
Operated by
Cleared staff on site

Typical for: Export-controlled and classified code

Access controls

Least privilege, always approved by you.

  • SSO via your identity provider (SAML / OIDC)
  • Phishing-resistant MFA for all personnel
  • Least-privilege, just-in-time access approved by you
  • Named engagement personnel only — no shared accounts
  • Background checks for personnel with data access
  • Access reviews at every engagement milestone

Audit logging

A complete record, in your hands.

  • Every routing decision and data access logged
  • Tamper-evident log storage
  • Export to your SIEM in standard formats
  • Retention governed by your policy

Retention policies

We keep as little as possible, for as short as possible.

  • Source code

    Not retained by us

    Stays in your environment and your approved models

  • Usage and session data for the audit

    Until engagement close

    Destroyed with written confirmation

  • Routing logs

    Per your policy

    Stored in your environment

  • Routing rules and runbooks

    Yours

    Delivered to you

  • Website inquiries

    Up to 24 months

    Deleted on request

Quality & oversight

Cheaper can't mean worse.

Every routing policy we ship is verified on your code, gated per job, and logged.

Verified before rollout

Routed work is compared with unrouted work on your own tasks before any team depends on it.

Per-job quality gates

Each job type stays on a cheaper model only while it meets your bar; the rest goes back to the frontier model.

Human review stays

Routing doesn't change your code review. Engineers still approve every change.

Routing transparency

Every routing decision is logged with the model used and the rule that sent it there.

Model terms respected

Worker models are chosen within the license and usage terms of each provider.

Framework alignment

Practices can be mapped to the NIST AI Risk Management Framework and ISO/IEC 42001 where you need them.

Documentation & disclosure

Everything your security review needs.

Security package

Policies, architecture, and completed questionnaires (SIG, CAIQ) under NDA.

Request

Vulnerability disclosure

Found an issue? We respond to good-faith reports promptly.

security@example.com

Subprocessors

Our current subprocessor list is available on request and updated before any change.

Request list

Security FAQ

Straight answers.

Do you train on our code?

No. Your code, prompts, and outputs are never used to train or improve any model.

Can routing run with no external APIs at all?

Yes. Worker models can be self-hosted, and routing can run fully inside an isolated network.

Who can see our code?

Only the models your routing policy allows, and only named engagement personnel you approve for the audit, with every access logged.

Will you complete our security questionnaire?

Yes. Send it with your request or to our security team, and we'll return it along with our security documentation under NDA.

Do you sign DPAs?

Yes. We execute data processing agreements for engagements involving personal data.

What happens to requests sent to third-party models?

Your routing policy decides which jobs may go to which providers. Sensitive repositories can be pinned to self-hosted models, and every external call is logged.

Security review

Bring us your hardest security review.

We'll walk your security, risk, and compliance teams through exactly how routing would run in your environment — before any code is discussed.

We respond within 1 business day. Mutual NDA available before any data discussion.