Governed, audited, portable.
Everything security review actually asks for: SSO, RBAC, SCIM, audit logs, zero-retention routing, SOC 2 Type II, DPA, private cloud.
SAML & OIDC SSO
Okta, Entra ID, Google Workspace, Auth0 and JumpCloud. Enforce SSO for every human user in your org.
SCIM provisioning
Sync users and groups from your IdP. Off-boarding removes access to keys and audit history in real time.
Roles & permissions
Owner, admin, developer, viewer, billing. Scope roles to projects. Ship least-privilege by default.
Immutable audit log
Every key operation, policy change, member action and API call — signed, timestamped, exportable to your SIEM.
SOC 2 Type II
Report available under NDA. GDPR-ready DPA, HIPAA BAA for eligible plans, EU data residency on request.
99.99% managed SLA
Service credits when we miss. Backed by multi-provider failover and multi-region posture.
Private cloud & VPC peering
Deploy a dedicated router in your AWS / GCP / Azure account. Keys and logs never leave your VPC.
White-label gateway
Ship a branded gateway and chat UI to your customers. Your domain, your logo, our routing.
Named account team
Solutions engineer, shared Slack channel, quarterly business review. On-call for P1 incidents.
Can we self-host?+
Yes — see Self-host. The open-source router runs the same routing, caching and observability stack as the managed cloud.
How does data residency work?+
Enterprise plans can constrain routing to providers in a specific region and pin the audit-log store to that region. EU-only and US-only postures are both supported.
Do you sign a DPA?+
Yes. Standard DPA is available at signup; custom DPAs handled through your account team.
Can we bring our own contracts with upstream providers?+
Yes — BYOK forwards to your accounts with your negotiated pricing and residency. The router still handles failover and observability.