Legal

Legal & compliance

Every agreement, policy, and compliance document for nRouter in one place. Enterprise and procurement teams: the Trust Center collects security, privacy, and uptime in a single view.

Agreements

Terms & policies

Enterprise

Data, SLA & subprocessors

Posture

Security & compliance

Compliance & Governance

Enterprise Compliance & Governance Architecture

nRouter is engineered from the ground up to satisfy the strictest enterprise regulatory mandates, data protection requirements, and information security standards across regulated global markets. Our compliance architecture enforces continuous automated control monitoring, immutable audit logging, and strict boundary separation.

SOC 2 Type II Controls

Our security program operates under AICPA trust services criteria across Security, Availability, and Confidentiality. A formal nRouter SOC 2 Type II observation window is currently in progress with independent auditors, while underlying cloud hosting infrastructure (Azure, Supabase) is fully SOC 2 Type II certified.

  • Automated continuous monitoring tracking cloud configurations, IAM policies, and cryptographic standards in real time.
  • Role-based access control (RBAC), multi-factor authentication (MFA) enforcement on all systems, and automated quarterly access certification.
  • Reports are available to enterprise prospects and procurement teams under mutual non-disclosure agreement (NDA) via the Trust Center.

GDPR & European Data Protection

Full compliance with the European General Data Protection Regulation (Regulation (EU) 2016/679). nRouter serves as a data processor for inference telemetry and customer payloads, providing a formal Data Processing Agreement incorporating European Commission Standard Contractual Clauses (SCCs).

  • Incorporates Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) Standard Contractual Clauses for legal international transfers.
  • Automated workflows for Data Subject Requests (DSR) honoring access, rectification, erasure (Right to be Forgotten), and data portability.
  • Designated Data Protection Officer (DPO) and formal 72-hour regulatory breach notification procedures under GDPR Article 33.

HIPAA Business Associate Agreement (BAA)

Enterprise healthcare and life sciences organizations can safely process Protected Health Information (PHI) through nRouter. We execute formal Business Associate Agreements (BAAs) defining mutual security obligations under 45 CFR Part 160 and Part 164 Subparts A and C.

  • Zero Data Retention (ZDR) configuration permanently disables payload logging to ensure no PHI is stored on persistent storage disks.
  • Strict technical safeguards: AES-256-GCM encryption at rest, TLS 1.3 in transit, and isolated tenant cryptographic contexts.
  • Comprehensive workforce compliance training, security background checks, and documented incident response runbooks.

ISO/IEC 27001 Posture & ISMS

Our Information Security Management System (ISMS) is modeled in strict alignment with ISO/IEC 27001:2022 specifications, providing a systematic approach to risk management, threat mitigation, vulnerability management, and business continuity.

  • Formal risk assessment methodology updated quarterly to evaluate newly emerging generative AI threat vectors and LLM vulnerabilities.
  • Automated dependency scanning, container vulnerability scans, static code analysis (SAST), and annual third-party penetration tests.
  • Comprehensive business continuity management with recovery point objectives (RPO < 1 min) and recovery time objectives (RTO < 15 min).
Privacy & Architecture

Data Privacy & Data Residency Principles

Our architectural philosophy is simple: your proprietary data belongs exclusively to you. We treat every inference request with zero-trust privacy controls, ensuring your intellectual property, user prompts, and completions never leak, persist unexpectedly, or get ingested into training pipelines.

Zero Prompt Training Guarantee

We provide an absolute contractual guarantee that neither customer prompts, model outputs, embeddings, nor fine-tuning datasets are ever used to train, retrain, or improve foundational AI models. This guarantee binds nRouter and our upstream model providers (OpenAI, Anthropic, Google Cloud, AWS Bedrock).

Our enterprise commercial agreements legally enforce zero-training commitments across every commercial API tier and endpoint. No customer conversation history is ever donated to public or private model weights.

Zero Data Retention by Default (ZDR)

All inference payload streams are proxied entirely in volatile RAM buffers. As soon as stream chunks are delivered to the client socket, buffer memory is immediately zeroed and reclaimed. No prompts, completions, or image payloads are ever written to disk or persistent storage databases.

Gateway spend logs retain strictly 22 non-content operational dimensions (request ID, tenant ID, virtual key ID, model identifier, provider, token counts, cost breakdown, latency, HTTP status code) for financial reconciliation and audit compliance.

Multi-Tenant Cryptographic Isolation

Tenant isolation is enforced across both data storage and runtime layers. Our PostgreSQL control plane enforces Row-Level Security (RLS) with mandatory tenant pinning on every query, connecting via transactional poolers configured with strict NOBYPASSRLS privileges to prevent cross-tenant data leakage.

Each organization's virtual API keys, routing configurations, spending budgets, and rate-limit buckets operate in isolated cryptographic namespaces. Gateway sidecar compute services operate under mutual TLS 1.3 with air-gapped network boundaries and zero direct database connectivity.

Regional Egress & Data Sovereignty

To satisfy regional sovereignty and regulatory requirements (such as EU Data Boundary and US federal mandates), nRouter supports geofenced inference routing policies. Customers can configure strict US-only, EU-only, or APAC-only egress rules.

When regional geofencing is activated, our routing engine restricts provider endpoint selection to deployments physically located within the designated ISO 3166-1 territory, preventing cross-border hops and ensuring compliance with local data sovereignty laws.

Vendor Management

Subprocessor Governance & Audit Rights

We maintain a rigorous vendor risk management program to ensure that any third-party infrastructure provider, cloud hosting partner, or payment processor adheres to security and confidentiality standards equivalent to our own.

Security Due Diligence & Vetting

Prior to onboarding any subprocessor, nRouter conducts a formal security risk assessment. We review third-party audit reports (SOC 2 Type II, ISO/IEC 27001), inspect data encryption standards, verify business continuity protocols, and validate that data protection agreements reflect required Standard Contractual Clauses (SCCs).

All subprocessors must agree to contractual terms obligating them to implement technical and organizational measures that meet or exceed nRouter's published Data Processing Agreement standards.

Review Cycles & Continuous Monitoring

Vendor risk assessments are not a one-time event. We perform scheduled annual re-certifications for all active subprocessors, gathering fresh audit reports, penetration testing summaries, and updated compliance attestations.

Our security engineering team continuously tracks automated threat intelligence feeds and security advisories affecting our subprocessor ecosystem, ensuring rapid remediation if a third-party security incident occurs.

Notification Timelines & Objection Rights

We maintain transparency regarding who handles customer data. nRouter commits to providing customers with at least 30 calendar days prior written notice before onboarding any new subprocessor that processes customer personal data.

Customers may subscribe to email notifications for subprocessor updates and have the contractual right to submit reasonable objections on data protection grounds. Our current public subprocessor directory is published and maintained at /legal/subprocessors.

Customer Audit Rights & Verification

Enterprise customers retain formal audit rights under our Data Processing Agreement. Customers can verify our compliance posture by reviewing our annual independent SOC 2 Type II audit report, penetration testing summaries, and completed standardized security questionnaires (such as CAIQ or SIG).

Where required by law or supervisory authorities, nRouter facilitates on-site or remote architectural security inspections conducted by independent certified auditors under agreed safety and confidentiality guidelines.

Commercial Terms

Terms of Service & Fair Use Summaries

A high-level summary of the essential covenants, obligations, and guarantees governing your organization's use of nRouter. For complete legal language, please review the authoritative Terms of Service.

Virtual Key Security & Account Ownership

Organizations maintain complete ownership and responsibility for securing their virtual API keys and administrative credentials. We provide granular tools to enforce least-privilege security, including per-key spending ceilings, model access whitelists, team-scoped access controls, and automated credential rotation.

If an organization suspects that an API key has been exposed or compromised, it must immediately revoke the key through the dashboard or API to halt egress.

Service Availability & SLA Commitments

Our high-availability gateway infrastructure is engineered for resilience, running across multiple geographic regions with automated health checks, provider circuit breakers, and sub-millisecond route failover.

Eligible Enterprise plans include a 99.99% monthly availability Service Level Agreement (SLA). In the event of unplanned downtime exceeding agreed error budgets, customers receive transparent financial service credits applied to their monthly billing invoice.

Acceptable Use & Abuse Prevention

nRouter enforces fair resource allocation and strictly prohibits harmful activities, including the generation of unlawful content, malicious prompt injection attacks against third parties, denial-of-service attempts, unauthorized penetration testing, or attempts to circumvent gateway metering.

Our edge WAF and preflight inspection layers enforce rate limiting (RPM/TPM) and guardrail scanning to protect overall system health and guarantee fair access for all tenants.

Pass-Through Pricing & Settlement

Models are offered at exact provider list prices with zero per-token markup. All billing follows a transparent two-tier funding structure: inference requests draw against your monthly subscription plan allowance first, overflowing to prepaid top-up credits only when extra usage is explicitly enabled.

Before upstream egress, a downward-adjusting credit reservation hold is placed based on estimated tokens. Upon stream completion, spend is settled to the exact millicent of list price, and any unused reservation hold is immediately released.

Questions about any of these documents or enterprise compliance terms? Email legal@nrouter.ai or contact our security and compliance team through the Trust Center.