Security
Security you can build on.
Apiframe sits in the critical path of your product, so we treat your data with care: encrypted everywhere, never used to train models, and served on infrastructure built to stay up.
Encryption everywhere
All data is encrypted in transit with TLS and at rest with AES-256. API keys are stored hashed and can be rotated at any time.
Never trained on your data
Your prompts and generated media are never used to train models. Your inputs and outputs are yours alone.
Built for reliability
Redundant infrastructure, health checks, and automatic provider failover keep generation running, backed by a 99.9% uptime SLA and a public status page.
Least-privilege access
Internal access to production systems follows the principle of least privilege, requires multi-factor authentication, and is logged for audit purposes.
Compliance & controls
Where things stand
We're transparent about what's live today and what's on the roadmap. Items marked coming soon are actively in progress.
No training on your data
Prompts and outputs are never used to train models.
Encryption everywhere
TLS in transit and AES-256 for stored data.
Audit logs
Track key usage and access across your organization.
GDPR-ready
Data handling and a signed DPA available on request.
SOC 2 Type II
Controls audited annually; report available under NDA.
SSO & SAML
Single sign-on and role-based access for your team.
Configurable retention
Set how long media is stored, or delete on your schedule.
Isolated regions
Data residency options for teams with locality needs.
Data handling
How we treat your data
The short version: it's yours. Here's exactly how inputs and outputs move through the platform.
Read the privacy policy for the full detail.
- You own your inputs and outputs. We process them only to deliver the generations you request.
- Generated content is not retained beyond what is necessary to complete your request, unless you explicitly opt into storage features.
- API request logs are retained for 90 days for security and debugging.
- To fulfill requests, necessary data is transmitted to the underlying AI model providers, each selected for appropriate data-protection standards.
- Access to production data is restricted on a need-to-know basis and audit-logged.
Found a vulnerability?
We appreciate responsible disclosure. Email our security team and we'll acknowledge your report within 24 hours and work with you on a fix. Valid reports may be eligible for recognition and rewards.
Power your next AI product with Apiframe.
Instant access to 70+ media models through a single API. Start free and scale when you're ready.