Security and data handling
- Read-only billing and usage access by default.
- No prompt or output review unless explicitly approved for a specific optimization.
- NDA and DPA available on request before any customer audit.
- Credential access should be scoped, time-bound, and revocable by the customer.
What access an engagement needs
The default is read-only billing and usage metadata: invoices, usage exports, and whatever request-level metadata already carries ownership tags. That is sufficient for baseline attribution and for identifying which workloads are worth optimizing. It does not require prompt content, output content, or production database access, and an engagement that asks for those on day one is asking for more than the work needs.
When content access is required
Some optimizations cannot be evaluated from metadata alone — semantic caching and prompt compression both depend on what is actually being sent. Where that applies, the scope is named in advance for the specific optimization, approved separately, and limited to sampled traffic rather than a standing feed. Approval for one optimization is not approval for the next.
Credential handling
- Scoped. Read-only keys limited to billing and usage endpoints, never account-admin credentials.
- Time-bound. Access is requested for the duration of the engagement and expected to be revoked at the end, by the customer, without asking us first.
- Customer-revocable at any time. Nothing in the workflow depends on continuous access; a revoked key stops the work, it does not break anything.
- Never shared across customers and never used to bootstrap a hosted service the customer did not ask for.
Reporting a vulnerability
If you find a security issue on this site or in anything we operate, email the address below with enough detail to reproduce it. We will confirm receipt, and we do not pursue researchers who report in good faith and do not access or retain other people's data while doing so.
Security contact: hello@finopsllm.com.