PhaseoPhaseo
PhaseoPhaseo
Checking statusChecking statusVisit status page
Component-level status is unavailable.

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

© 2025 • Phaseo

Report:Issue·Support

Spotted a data issue or broken page?Open an issueorcontact support

PhaseoPhaseo
ModelsChatCompareProvidersAppsRankings
ModelsChatCompareProvidersAppsRankings
Phaseo Trust Centre

Trust is a record of what is true now.

A plain account of Phaseo's current security and data posture. Product capabilities, internal assertions, gated features, plans, and external certifications are labelled separately.

Assurance levelSelf-attested

Phaseo is not SOC 2 or ISO 27001 certified. The practices on this page are supported by current product code, public policies, and operating documentation, but have not been independently audited as a programme.

Reviewed 23 August 2026

Claim labels

Available

In the product today.

Gated

Available only to eligible workspaces or configurations.

Self-attested

Described from Phaseo's own code, policy, and operations; not independently audited.

Planned

Intended work, with no delivery date promised.

Independently certified

Verified by an external certification body. Phaseo has none today.

Security practices

Controls we can point to without disclosing sensitive configuration.

Encrypted transport

Phaseo's public service is delivered over HTTPS. Requests are forwarded to model providers over encrypted HTTPS connections.

Self-attested

Provider key protection

Bring-your-own provider credentials are encrypted with AES-256-GCM before storage. OAuth client secrets are stored as peppered SHA-256 hashes.

Self-attested

Scoped access and OAuth

Workspace roles and scoped API or OAuth permissions limit access. OAuth connections expose their requested permissions through a consent flow and can be revoked.

Available

Enterprise identity

SAML single sign-on and SCIM user and group provisioning exist behind workspace entitlement and feature gates; they are not baseline features for every account.

Gated

Private vulnerability reporting

Reports can be submitted through GitHub Security Advisories or security@phaseo.app. Phaseo targets acknowledgement within three business days.

Available

Data handling

The default path, explicit exceptions, and provider boundary.

Gateway content by default

Raw prompt and full model-output text is not persistently stored in Phaseo's primary database or analytics tools. Content passes through transient processing buffers and the selected model provider.

Self-attested

Optional data contribution

This is opt-in. Eligible prompts and completions may be redacted and retained for no more than 30 days; revoking consent stops new capture and queues prior captures for deletion.

Available

Provider retention and training

Phaseo cannot promise zero data retention across every model provider. Downstream handling follows the provider and route you use; review that provider's policy before sending sensitive data.

Self-attested

Regional routing

Provider and geography controls can constrain eligible routes, but Phaseo does not currently promise end-to-end data residency for every request.

Gated

Service providers

The categories publicly disclosed in Phaseo's privacy posture.

ProviderPurposeData involved
Hosting providers
Host and deliver the service
Service traffic and operational metadata needed to run Phaseo
Supabase
Database and account infrastructure
Account, workspace, configuration, and request metadata
Stripe
Payments and billing
Billing identity and transaction records; Phaseo does not store full card details
Analytics providers
Product analytics and error diagnosis
Page, device, and usage telemetry; configured to exclude raw gateway prompts and outputs
Email and support providers
Service communications and customer support
Contact details, message contents, and related account context
Model providers
Process the inference request you route
Inputs, outputs, and necessary request metadata; provider terms and retention apply
Connected assistant providers
Return authorised OAuth tool results
Only the read-only result and scopes approved through the consent flow
This is a concise public disclosure, not a contractual subprocessor schedule. Model providers vary by the route selected. See the Privacy Policy for the governing description.

Availability & incidents

Public status

Current service health and component incidents are published at status.phaseo.app.

No contractual public uptime SLA is claimed.

Incident response

Operational code includes incident notification and outreach paths. Phaseo does not publish internal playbooks or claim that this process has been independently tested.

Self-attested

Compliance posture

Clear negative claims matter as much as positive ones.

No independent certification today

Planned

A formal assurance programme may be considered as customer need and budget justify it. No framework, auditor, scope, or completion date is committed.

  • SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent Phaseo certification
  • A completed independent penetration test or published audit report
  • A contractual uptime SLA for the public service
  • Universal zero data retention or a guarantee that providers do not train on request data
  • Guaranteed regional data residency for every provider and route
  • A downloadable DPA, security whitepaper, or compliance report
Responsible disclosure

Found something that could put users at risk?

Please report it privately. Avoid accessing other people's data, denial-of-service testing, or public disclosure before a fix is available.

Email securityPrivate GitHub report
Privacy PolicyTerms of ServiceContact support
Claims reviewed against repository evidence
Sign Up