Security first

Security at Every Layer

Zero data retention. EU hosting. Enterprise-grade security by default. Your data never leaves your control.

Or email us at sales@requesty.ai

Zero Data Retention

Your prompts and completions are never stored. Data is proxied in real-time and immediately discarded after delivery.

EU Data Residency

All data processed through our EU infrastructure. Full GDPR compliance with data never leaving European borders.

End-to-End Encryption

TLS 1.3 encryption for all data in transit. AES-256 for any data at rest. Zero plaintext exposure.

01Live

Threat detection, in real time

Every request is inspected before it leaves the gateway. Shadow AI, non-EU egress, prompt injection, leaked secrets: caught and logged as they happen.

Threats blocked
847
last 24h
PII tokens scrubbed
23.4k
last 24h
Non-EU egress blocked
112
last 24h
Shadow-AI attempts
34
last 24h
Live event streamgateway · eu-frankfurt
BLOCKEDShadow AI 

Unauthorized model rejected

openclaw-72b @ prc-cloud.ai/v1

from eng-team-3

BLOCKEDCompliance 

Chinese-hosted model blocked

deepseek-v3 @ cn-north-1, not in allowlist

from key: req_dev_k3x

BLOCKEDData Egress 

Non-EU endpoint rejected

policy violation: *.us-east-1.amazonaws.com

from policy: eu_only

SCRUBBEDPII 

3 PII tokens scrubbed before model call

email · ssn · credit_card

from svc-backend-prod

Threat pulseEvents per minute · last 60 min
BLOCKEDSCRUBBEDWARNINGALLOWED
Top blocked categories
Shadow AI models38%
Non-EU egress27%
Prompt injection18%
PII in prompts12%
Leaked secrets5%

02Guardrails

Built-in Guardrails

Enterprise-grade security controls that work out of the box

PII Detection & Scrubbing

Automatically detect and mask personally identifiable information before it reaches the model

Prompt Injection Protection

Real-time detection and blocking of prompt injection attempts

Content Filtering

Configurable content policies to prevent harmful outputs

Rate Limiting

Per-key, per-team, and per-model rate limits to prevent abuse

Spending Controls

Set budgets per team, per user, or per API key with automatic cutoffs

Audit Logging

Complete audit trail of every request with timestamps, users, and models used

03Compliance

Compliance & Certifications

Meeting the highest standards for security and privacy

GDPR Compliant

Full compliance with EU data protection regulations

SOC 2 Type II

In progress - expected Q3 2026

Data processed in EU

All infrastructure hosted in Frankfurt, Germany

No third-party data sharing

Your data is never shared with third parties

Regular security audits

Quarterly penetration testing and security reviews

Responsible disclosure program

We reward security researchers for responsible disclosure

04Architecture

Secure Architecture

Your data flows through our secure gateway, never stored

  1. Your App

    Your application

  2. Requesty Gateway

    Frankfurt, EU

    No data storedPII scrubbedAudit logged
  3. Model Providers

    OpenAI, Anthropic, etc.

End-to-end encrypted

TLS 1.3 everywhere

Zero retention

No data stored

Full audit trail

Every request logged

Security FAQ

Common security and compliance questions from teams evaluating Requesty.

Is my data encrypted?

Yes. All traffic is encrypted in transit with TLS 1.2 or higher, and all data at rest is encrypted with AES-256. Credentials and API keys are stored encrypted and never logged.

How does PII detection work?

Requesty runs prompts through a proprietary PII detection model before they reach the model provider. Detected PII can be automatically scrubbed, flagged, or blocked based on your policy. The detector covers names, emails, phone numbers, SSNs, credit card numbers, and custom regex patterns.

Can I block specific models or providers?

Yes. Admins can restrict access to an approved list of models and providers. Users calling a blocked model get a clear error, and every attempt is logged for audit.

Do you retain my prompts or completions?

On self serve plans, prompt and output logging is enabled by default and retained for up to 30 days in encrypted form within the EU, and you can disable it per API key at any time. Organisation wide Zero Data Retention, under which no prompt or output content is persisted and our own caching is disabled, is enabled on written request. Audit logs record metadata (timestamp, user, model, token counts, cost) in every configuration, so you can trace activity without exposing prompt content.

Is Requesty SOC 2 compliant?

Our SOC 2 Type II programme is in progress. Our current certification and audit status is published at trust.requesty.ai, and we make no representation of certification beyond what is stated there. We are GDPR compliant, provide a DPA on request, and support EU data residency in Frankfurt.

How are API keys protected?

API keys are hashed at rest and shown in full only once at creation. Admins can rotate, revoke, or set spend limits per key. Service accounts let you issue scoped keys for CI/CD without exposing user credentials.

Security shouldn't be an afterthought

Start building with enterprise-grade security from day one.