Legal & compliance
Every agreement, policy, and compliance document for nRouter in one place. Enterprise and procurement teams: the Trust Center collects security, privacy, and uptime in a single view.
Terms & policies
Terms of Service
The agreement that governs your use of nRouter — accounts, credits, acceptable use, and liability.
Privacy Policy
What data we collect, how we use it, retention windows, and your rights as a data subject.
Acceptable Use Policy
Guidelines and restrictions for using the platform — prohibited content, abuse, and rate fairness.
Cookie Policy
The cookies and similar technologies we use on nrouter.ai and how to control them.
Data, SLA & subprocessors
Data Processing Agreement
GDPR/CCPA-aligned DPA covering how nRouter processes personal data on your behalf.
Service Level Agreement
Uptime commitment, measurement methodology, and service credits for eligible plans.
Subprocessors
The third-party infrastructure and service providers we use to deliver nRouter.
Security & compliance
Security
Encryption, access controls, key isolation, and how we protect customer data and credentials.
Compliance
Our compliance program, certifications in progress, and how we map controls to frameworks.
Trust Center
A single view of security, privacy, uptime, and compliance for procurement and security reviews.
Enterprise Compliance & Governance Architecture
nRouter is engineered from the ground up to satisfy the strictest enterprise regulatory mandates, data protection requirements, and information security standards across regulated global markets. Our compliance architecture enforces continuous automated control monitoring, immutable audit logging, and strict boundary separation.
SOC 2 Type II Controls
Our security program operates under AICPA trust services criteria across Security, Availability, and Confidentiality. A formal nRouter SOC 2 Type II observation window is currently in progress with independent auditors, while underlying cloud hosting infrastructure (Azure, Supabase) is fully SOC 2 Type II certified.
- Automated continuous monitoring tracking cloud configurations, IAM policies, and cryptographic standards in real time.
- Role-based access control (RBAC), multi-factor authentication (MFA) enforcement on all systems, and automated quarterly access certification.
- Reports are available to enterprise prospects and procurement teams under mutual non-disclosure agreement (NDA) via the Trust Center.
GDPR & European Data Protection
Full compliance with the European General Data Protection Regulation (Regulation (EU) 2016/679). nRouter serves as a data processor for inference telemetry and customer payloads, providing a formal Data Processing Agreement incorporating European Commission Standard Contractual Clauses (SCCs).
- Incorporates Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) Standard Contractual Clauses for legal international transfers.
- Automated workflows for Data Subject Requests (DSR) honoring access, rectification, erasure (Right to be Forgotten), and data portability.
- Designated Data Protection Officer (DPO) and formal 72-hour regulatory breach notification procedures under GDPR Article 33.
HIPAA Business Associate Agreement (BAA)
Enterprise healthcare and life sciences organizations can safely process Protected Health Information (PHI) through nRouter. We execute formal Business Associate Agreements (BAAs) defining mutual security obligations under 45 CFR Part 160 and Part 164 Subparts A and C.
- Zero Data Retention (ZDR) configuration permanently disables payload logging to ensure no PHI is stored on persistent storage disks.
- Strict technical safeguards: AES-256-GCM encryption at rest, TLS 1.3 in transit, and isolated tenant cryptographic contexts.
- Comprehensive workforce compliance training, security background checks, and documented incident response runbooks.
ISO/IEC 27001 Posture & ISMS
Our Information Security Management System (ISMS) is modeled in strict alignment with ISO/IEC 27001:2022 specifications, providing a systematic approach to risk management, threat mitigation, vulnerability management, and business continuity.
- Formal risk assessment methodology updated quarterly to evaluate newly emerging generative AI threat vectors and LLM vulnerabilities.
- Automated dependency scanning, container vulnerability scans, static code analysis (SAST), and annual third-party penetration tests.
- Comprehensive business continuity management with recovery point objectives (RPO < 1 min) and recovery time objectives (RTO < 15 min).
Data Privacy & Data Residency Principles
Our architectural philosophy is simple: your proprietary data belongs exclusively to you. We treat every inference request with zero-trust privacy controls, ensuring your intellectual property, user prompts, and completions never leak, persist unexpectedly, or get ingested into training pipelines.
Zero Prompt Training Guarantee
We provide an absolute contractual guarantee that neither customer prompts, model outputs, embeddings, nor fine-tuning datasets are ever used to train, retrain, or improve foundational AI models. This guarantee binds nRouter and our upstream model providers (OpenAI, Anthropic, Google Cloud, AWS Bedrock).
Our enterprise commercial agreements legally enforce zero-training commitments across every commercial API tier and endpoint. No customer conversation history is ever donated to public or private model weights.
Zero Data Retention by Default (ZDR)
All inference payload streams are proxied entirely in volatile RAM buffers. As soon as stream chunks are delivered to the client socket, buffer memory is immediately zeroed and reclaimed. No prompts, completions, or image payloads are ever written to disk or persistent storage databases.
Gateway spend logs retain strictly 22 non-content operational dimensions (request ID, tenant ID, virtual key ID, model identifier, provider, token counts, cost breakdown, latency, HTTP status code) for financial reconciliation and audit compliance.
Multi-Tenant Cryptographic Isolation
Tenant isolation is enforced across both data storage and runtime layers. Our PostgreSQL control plane enforces Row-Level Security (RLS) with mandatory tenant pinning on every query, connecting via transactional poolers configured with strict NOBYPASSRLS privileges to prevent cross-tenant data leakage.
Each organization's virtual API keys, routing configurations, spending budgets, and rate-limit buckets operate in isolated cryptographic namespaces. Gateway sidecar compute services operate under mutual TLS 1.3 with air-gapped network boundaries and zero direct database connectivity.
Regional Egress & Data Sovereignty
To satisfy regional sovereignty and regulatory requirements (such as EU Data Boundary and US federal mandates), nRouter supports geofenced inference routing policies. Customers can configure strict US-only, EU-only, or APAC-only egress rules.
When regional geofencing is activated, our routing engine restricts provider endpoint selection to deployments physically located within the designated ISO 3166-1 territory, preventing cross-border hops and ensuring compliance with local data sovereignty laws.
Subprocessor Governance & Audit Rights
We maintain a rigorous vendor risk management program to ensure that any third-party infrastructure provider, cloud hosting partner, or payment processor adheres to security and confidentiality standards equivalent to our own.
Security Due Diligence & Vetting
Prior to onboarding any subprocessor, nRouter conducts a formal security risk assessment. We review third-party audit reports (SOC 2 Type II, ISO/IEC 27001), inspect data encryption standards, verify business continuity protocols, and validate that data protection agreements reflect required Standard Contractual Clauses (SCCs).
All subprocessors must agree to contractual terms obligating them to implement technical and organizational measures that meet or exceed nRouter's published Data Processing Agreement standards.
Review Cycles & Continuous Monitoring
Vendor risk assessments are not a one-time event. We perform scheduled annual re-certifications for all active subprocessors, gathering fresh audit reports, penetration testing summaries, and updated compliance attestations.
Our security engineering team continuously tracks automated threat intelligence feeds and security advisories affecting our subprocessor ecosystem, ensuring rapid remediation if a third-party security incident occurs.
Notification Timelines & Objection Rights
We maintain transparency regarding who handles customer data. nRouter commits to providing customers with at least 30 calendar days prior written notice before onboarding any new subprocessor that processes customer personal data.
Customers may subscribe to email notifications for subprocessor updates and have the contractual right to submit reasonable objections on data protection grounds. Our current public subprocessor directory is published and maintained at /legal/subprocessors.
Customer Audit Rights & Verification
Enterprise customers retain formal audit rights under our Data Processing Agreement. Customers can verify our compliance posture by reviewing our annual independent SOC 2 Type II audit report, penetration testing summaries, and completed standardized security questionnaires (such as CAIQ or SIG).
Where required by law or supervisory authorities, nRouter facilitates on-site or remote architectural security inspections conducted by independent certified auditors under agreed safety and confidentiality guidelines.
Terms of Service & Fair Use Summaries
A high-level summary of the essential covenants, obligations, and guarantees governing your organization's use of nRouter. For complete legal language, please review the authoritative Terms of Service.
Virtual Key Security & Account Ownership
Organizations maintain complete ownership and responsibility for securing their virtual API keys and administrative credentials. We provide granular tools to enforce least-privilege security, including per-key spending ceilings, model access whitelists, team-scoped access controls, and automated credential rotation.
If an organization suspects that an API key has been exposed or compromised, it must immediately revoke the key through the dashboard or API to halt egress.
Service Availability & SLA Commitments
Our high-availability gateway infrastructure is engineered for resilience, running across multiple geographic regions with automated health checks, provider circuit breakers, and sub-millisecond route failover.
Eligible Enterprise plans include a 99.99% monthly availability Service Level Agreement (SLA). In the event of unplanned downtime exceeding agreed error budgets, customers receive transparent financial service credits applied to their monthly billing invoice.
Acceptable Use & Abuse Prevention
nRouter enforces fair resource allocation and strictly prohibits harmful activities, including the generation of unlawful content, malicious prompt injection attacks against third parties, denial-of-service attempts, unauthorized penetration testing, or attempts to circumvent gateway metering.
Our edge WAF and preflight inspection layers enforce rate limiting (RPM/TPM) and guardrail scanning to protect overall system health and guarantee fair access for all tenants.
Pass-Through Pricing & Settlement
Models are offered at exact provider list prices with zero per-token markup. All billing follows a transparent two-tier funding structure: inference requests draw against your monthly subscription plan allowance first, overflowing to prepaid top-up credits only when extra usage is explicitly enabled.
Before upstream egress, a downward-adjusting credit reservation hold is placed based on estimated tokens. Upon stream completion, spend is settled to the exact millicent of list price, and any unused reservation hold is immediately released.
Questions about any of these documents or enterprise compliance terms? Email legal@nrouter.ai or contact our security and compliance team through the Trust Center.