Security first
Security at Every Layer
Zero data retention. EU hosting. Enterprise-grade security by default. Your data never leaves your control.
Or email us at sales@requesty.ai
Your prompts and completions are never stored. Data is proxied in real-time and immediately discarded after delivery.
All data processed through our EU infrastructure. Full GDPR compliance with data never leaving European borders.
TLS 1.3 encryption for all data in transit. AES-256 for any data at rest. Zero plaintext exposure.
01Live
Threat detection, in real time
Every request is inspected before it leaves the gateway. Shadow AI, non-EU egress, prompt injection, leaked secrets: caught and logged as they happen.
Unauthorized model rejected
openclaw-72b @ prc-cloud.ai/v1
from eng-team-3
Chinese-hosted model blocked
deepseek-v3 @ cn-north-1, not in allowlist
from key: req_dev_k3x
Non-EU endpoint rejected
policy violation: *.us-east-1.amazonaws.com
from policy: eu_only
3 PII tokens scrubbed before model call
email · ssn · credit_card
from svc-backend-prod
02Guardrails
Built-in Guardrails
Enterprise-grade security controls that work out of the box
PII Detection & Scrubbing
Automatically detect and mask personally identifiable information before it reaches the model
Prompt Injection Protection
Real-time detection and blocking of prompt injection attempts
Content Filtering
Configurable content policies to prevent harmful outputs
Rate Limiting
Per-key, per-team, and per-model rate limits to prevent abuse
Spending Controls
Set budgets per team, per user, or per API key with automatic cutoffs
Audit Logging
Complete audit trail of every request with timestamps, users, and models used
03Compliance
Compliance & Certifications
Meeting the highest standards for security and privacy
GDPR Compliant
Full compliance with EU data protection regulations
SOC 2 Type II
In progress - expected Q3 2026
Data processed in EU
All infrastructure hosted in Frankfurt, Germany
No third-party data sharing
Your data is never shared with third parties
Regular security audits
Quarterly penetration testing and security reviews
Responsible disclosure program
We reward security researchers for responsible disclosure
04Architecture
Secure Architecture
Your data flows through our secure gateway, never stored
Your App
Your application
Requesty Gateway
Frankfurt, EU
No data storedPII scrubbedAudit loggedModel Providers
OpenAI, Anthropic, etc.
End-to-end encrypted
TLS 1.3 everywhere
Zero retention
No data stored
Full audit trail
Every request logged
Security FAQ
Common security and compliance questions from teams evaluating Requesty.
Is my data encrypted?
Yes. All traffic is encrypted in transit with TLS 1.2 or higher, and all data at rest is encrypted with AES-256. Credentials and API keys are stored encrypted and never logged.
How does PII detection work?
Requesty runs prompts through a proprietary PII detection model before they reach the model provider. Detected PII can be automatically scrubbed, flagged, or blocked based on your policy. The detector covers names, emails, phone numbers, SSNs, credit card numbers, and custom regex patterns.
Can I block specific models or providers?
Yes. Admins can restrict access to an approved list of models and providers. Users calling a blocked model get a clear error, and every attempt is logged for audit.
Do you retain my prompts or completions?
On self serve plans, prompt and output logging is enabled by default and retained for up to 30 days in encrypted form within the EU, and you can disable it per API key at any time. Organisation wide Zero Data Retention, under which no prompt or output content is persisted and our own caching is disabled, is enabled on written request. Audit logs record metadata (timestamp, user, model, token counts, cost) in every configuration, so you can trace activity without exposing prompt content.
Is Requesty SOC 2 compliant?
Our SOC 2 Type II programme is in progress. Our current certification and audit status is published at trust.requesty.ai, and we make no representation of certification beyond what is stated there. We are GDPR compliant, provide a DPA on request, and support EU data residency in Frankfurt.
How are API keys protected?
API keys are hashed at rest and shown in full only once at creation. Admins can rotate, revoke, or set spend limits per key. Service accounts let you issue scoped keys for CI/CD without exposing user credentials.
Security shouldn't be an afterthought
Start building with enterprise-grade security from day one.
