Encrypted transport
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
A plain account of Phaseo's current security and data posture. Product capabilities, internal assertions, gated features, plans, and external certifications are labelled separately.
Phaseo is not SOC 2 or ISO 27001 certified. The practices on this page are supported by current product code, public policies, and operating documentation, but have not been independently audited as a programme.
Reviewed 23 August 2026
In the product today.
Available only to eligible workspaces or configurations.
Described from Phaseo's own code, policy, and operations; not independently audited.
Intended work, with no delivery date promised.
Verified by an external certification body. Phaseo has none today.
Controls we can point to without disclosing sensitive configuration.
Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.
Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. OAuth client secrets are stored as peppered SHA-256 hashes.
Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.
SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.
Reports can be submitted through GitHub Security Advisories or security@phaseo.app. Phaseo targets acknowledgement within three business days.
The default path, explicit exceptions, and provider boundary.
Raw prompt and full model-output text is not persistently stored in Phaseo's primary database or analytics tools. Content passes through transient processing buffers and the selected model provider.
This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.
Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.
Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.
The categories publicly disclosed in Phaseo's privacy posture.
Current service health and component incidents are published at status.phaseo.app.
No contractual public uptime SLA is claimed.
Operational code includes incident notification and outreach paths. Phaseo does not publish internal playbooks or claim that this process has been independently tested.
Self-attestedClear negative claims matter as much as positive ones.
A formal assurance programme may be considered as customer need and budget justify it. No framework, auditor, scope, or completion date is committed.
Please report it privately. Avoid accessing other people's data, denial-of-service testing, or public disclosure before a fix is available.