Requesty
Security first

Security at Every Layer

Zero data retention on request. EU hosting. Enterprise-grade controls by default, and you decide what is logged.

Speak to founders

Or email us at sales@requesty.ai

Core security principles

Zero Data Retention

Turn logging off per API key, or enable organisation wide zero data retention on request, and prompts and completions are never persisted.

EU Data Residency

All data processed through our EU infrastructure. Full GDPR compliance with data never leaving European borders.

End-to-End Encryption

TLS 1.3 encryption for all data in transit. AES-256 for any data at rest. Zero plaintext exposure.

Live

Threat detection, in real time

Every request is inspected before it leaves the gateway. Shadow AI, non-EU egress, prompt injection, leaked secrets, all caught and logged as they happen.

Threats blocked
847last 24h
PII tokens scrubbed
23.4klast 24h
Non-EU egress blocked
112last 24h
Shadow-AI attempts
34last 24h
Live event stream
gateway · eu-frankfurt
BLOCKEDShadow AI12:54:21

Unauthorized model rejected

openclaw-72b @ prc-cloud.ai/v1

from eng-team-3

BLOCKEDCompliance12:54:14

Chinese-hosted model blocked

deepseek-v3 @ cn-north-1, not in allowlist

from key: req_dev_k3x

BLOCKEDData Egress12:54:07

Non-EU endpoint rejected

policy violation: *.us-east-1.amazonaws.com

from policy: eu_only

SCRUBBEDPII12:54:00

3 PII tokens scrubbed before model call

email · ssn · credit_card

from svc-backend-prod

Threat pulse

Events per minute, last 60 min

BLOCKED
SCRUBBED
WARNING
ALLOWED
-60m-45m-30m-15mnow

Top blocked categories

Shadow AI models38%
Non-EU egress27%
Prompt injection18%
PII in prompts12%
Leaked secrets5%

Built-in Guardrails

Enterprise-grade security controls that work out of the box

PII Detection & Scrubbing

Automatically detect and mask personally identifiable information before it reaches the model

Prompt Injection Protection

Real-time detection and blocking of prompt injection attempts

Content Filtering

Configurable content policies to prevent harmful outputs

Rate Limiting

Per-key, per-team, and per-model rate limits to prevent abuse

Spending Controls

Set budgets per team, per user, or per API key with automatic cutoffs

Audit Logging

Complete audit trail of every request with timestamps, users, and models used

Compliance & Certifications

Meeting the highest standards for security and privacy

GDPR Compliant

Full compliance with EU data protection regulations

SOC 2 Type II

In progress - expected Q3 2026

Data processed in EU

All infrastructure hosted in Frankfurt, Germany

No third-party data sharing

Your data is never shared with third parties

Regular security audits

Quarterly penetration testing and security reviews

Responsible disclosure program

We reward security researchers for responsible disclosure

Secure Architecture

Your data flows through our gateway, and with zero data retention it is never stored

Your App

Your application

TLS 1.3

Requesty Gateway

Frankfurt, EU

No data storedPII scrubbedAudit logged
TLS 1.3

Model Providers

OpenAI, Anthropic, etc.

End-to-end encrypted

TLS 1.3 everywhere

Zero retention

No data stored

Full audit trail

Every request logged

Security FAQ

Common security and compliance questions from teams evaluating Requesty.

Yes. All traffic is encrypted in transit with TLS 1.2 or higher, and all data at rest is encrypted with AES-256. Credentials and API keys are stored encrypted and never logged.

Requesty runs prompts through a proprietary PII detection model before they reach the model provider. Detected PII can be automatically scrubbed, flagged, or blocked based on your policy. The detector covers names, emails, phone numbers, SSNs, credit card numbers, and custom regex patterns.

Yes. Admins can restrict access to an approved list of models and providers. Users calling a blocked model get a clear error, and every attempt is logged for audit.

On self serve plans, prompt and output logging is enabled by default and retained for up to 30 days in encrypted form within the EU, and you can disable it per API key at any time. Organisation wide Zero Data Retention, under which no prompt or output content is persisted and our own caching is disabled, is enabled on written request. Audit logs record metadata (timestamp, user, model, token counts, cost) in every configuration, so you can trace activity without exposing prompt content.

Our SOC 2 Type II programme is in progress. Our current certification and audit status is published at trust.requesty.ai, and we make no representation of certification beyond what is stated there. We are GDPR compliant, provide a DPA on request, and support EU data residency in Frankfurt.

API keys are hashed at rest and shown in full only once at creation. Admins can rotate, revoke, or set spend limits per key. Service accounts let you issue scoped keys for CI/CD without exposing user credentials.

Security is not an afterthought

Start on enterprise-grade controls from day one.

Speak to founders