Requesty
Security

You decide what is kept, where it runs, and what gets through.

Encrypted in transit and at rest. Logging you can turn off per key, or off for the whole organization. An EU gateway in Frankfurt. And a set of checks that refuse a request before any provider sees it.

Speak to founders
TLS 1.2+ and AES-256zero data retention on requestEU gateway in Frankfurtstatus at trust.requesty.ai
logs / refused and redacted
last 3 minutes
model not approved
some-lab/preview · 403 policy_violation
14:22:09
request via rejected gateway
router.us.requesty.ai · org restricted to EU
14:21:51
3 PII values masked
email · card number · phone
14:21:30
prompt injection blocked
"ignore previous instructions and…"
14:20:58
non-ZDR endpoint excluded
policy requires zero data retention
14:20:12
cap reached, request refused
sk-agent-eval · $500 of $500
14:19:47
Every one of these happened before a provider saw the request.
Data handling

Your prompts, on your terms

Logging is on by default, encrypted, in the EU, for 30 days. Turn it off per key and only metadata remains. Ask for organization-wide zero data retention and nothing is persisted at all.

  • Per keyOff for the legal team, on for the sandbox
  • Metadata still auditsTimestamp, user, model, tokens, cost
settings / data retention
per key
Prompt and output logging
sk-prod-apilogging
sk-support-botlogging
sk-legal-reviewoff
sk-agent-evaloff
Organization-wide zero data retention
On written request. No prompt or output content is persisted and gateway caching is disabled. Audit logs keep metadata only.
Encryption and keys

Keys that can only do what you said

TLS 1.2 or higher in transit, AES-256 at rest. Keys are hashed, shown once, and carry their own access list and spend cap. Service accounts give CI and agents a key that is not a person's.

settings / api keys
hashed at rest
sk-prod-apisvc-checkout4 models · chat only2 min ago
sk-support-botsupport-ai2 models · guardrails on9 min ago
sk-ci-evalsvc-ci1 model · $60 cap3 h ago
sk-legacy-0a12dana@acme-increvokedrevoked today
shown in full once, at creationrotate or revoke without a deploy
Request path

Three hops. Every check on the middle one.

Your application talks to the gateway in the region you chose. The gateway applies the organization's policy and forwards only what passes, only to the endpoints the policy allows.

01 / your application
Your application
any SDK, any language
TLS 1.2 or higher to the gateway
API key hashed on our side
02 / requesty gateway
every request
Requesty gateway
the region you chose
approved models checked
PII masked, injection blocked
budget and access list applied
logged per your retention setting
03 / model provider
Model provider
only endpoints your policy allows
TLS onward
zero data retention terms when required
Compliance

Claims you can check

Each row names where the current status lives. Nothing here is asserted beyond what those pages say.

compliance / status
September 2026
ItemStatusVerify at
SOC 2 Type IIprogramme in progresstrust.requesty.ai
GDPR, Article 28 DPAsigned on request, any spendsub-processors list
EU data residencyFrankfurt, eu-central-1requesty.ai/eu
Zero data retentionper key, or org-wide on requestdocs
EncryptionTLS 1.2+ in transit, AES-256 at resttrust.requesty.ai

Questions security teams ask

Yes. All traffic is encrypted in transit with TLS 1.2 or higher, and all data at rest is encrypted with AES-256. Credentials and API keys are stored encrypted and never logged.

Requesty runs prompts through a PII detection model before they reach the model provider. Detected PII can be masked, flagged or blocked based on your policy. The detector covers names, emails, phone numbers, SSNs, credit card numbers and custom regex patterns.

Yes. Administrators can restrict the organization, or a group, to an approved list of models. A call to anything else gets a clear 403, and every attempt is logged for audit.

On self serve plans, prompt and output logging is on by default and retained for up to 30 days in encrypted form within the EU. You can turn it off per API key at any time. Organization-wide zero data retention, under which no prompt or output content is persisted and our own caching is disabled, is enabled on written request. Audit logs record metadata (timestamp, user, model, token counts, cost) in every configuration.

Our SOC 2 Type II programme is in progress. Current certification and audit status is published at trust.requesty.ai, and we make no representation of certification beyond what is stated there. We are GDPR compliant, provide a DPA on request, and support EU data residency in Frankfurt.

API keys are hashed at rest and shown in full only once, at creation. Administrators can rotate or revoke a key and set spend limits and access lists per key. Service accounts let you issue scoped keys for CI and agents without exposing a person’s credentials.

Rolling it out

The controls are on every plan. Enterprise adds the paperwork.

SSO, a procurement process run by people, and a DPA on request.

Put the checks on the request path

Start on the same controls the largest teams run on.

Speak to founders