Need a security review? Talk to our team.

Security

Security you can build on.

Apiframe sits in the critical path of your product, so we treat your data with care: encrypted everywhere, never used to train models, and served on infrastructure built to stay up.

Encryption everywhere

All data is encrypted in transit with TLS and at rest with AES-256. API keys are stored hashed and can be rotated at any time.

Never trained on your data

Your prompts and generated media are never used to train models. Your inputs and outputs are yours alone.

Built for reliability

Redundant infrastructure, health checks, and automatic provider failover keep generation running, backed by a 99.9% uptime SLA and a public status page.

Least-privilege access

Internal access to production systems follows the principle of least privilege, requires multi-factor authentication, and is logged for audit purposes.

Compliance & controls

Where things stand

We're transparent about what's live today and what's on the roadmap. Items marked coming soon are actively in progress.

No training on your data

Prompts and outputs are never used to train models.

Encryption everywhere

TLS in transit and AES-256 for stored data.

Audit logs

Track key usage and access across your organization.

Coming soon

GDPR-ready

Data handling and a signed DPA available on request.

Coming soon

SOC 2 Type II

Controls audited annually; report available under NDA.

Coming soon

SSO & SAML

Single sign-on and role-based access for your team.

Coming soon

Configurable retention

Set how long media is stored, or delete on your schedule.

Coming soon

Isolated regions

Data residency options for teams with locality needs.

Data handling

How we treat your data

The short version: it's yours. Here's exactly how inputs and outputs move through the platform.

Read the privacy policy for the full detail.

  • You own your inputs and outputs. We process them only to deliver the generations you request.
  • Generated content is not retained beyond what is necessary to complete your request, unless you explicitly opt into storage features.
  • API request logs are retained for 90 days for security and debugging.
  • To fulfill requests, necessary data is transmitted to the underlying AI model providers, each selected for appropriate data-protection standards.
  • Access to production data is restricted on a need-to-know basis and audit-logged.

Found a vulnerability?

We appreciate responsible disclosure. Email our security team and we'll acknowledge your report within 24 hours and work with you on a fix. Valid reports may be eligible for recognition and rewards.

[email protected]

Power your next AI product with Apiframe.

Instant access to 70+ media models through a single API. Start free and scale when you're ready.