We sit inline on your traffic. Here’s exactly how we keep that safe.
Trust is earned, not asserted. Built for the spend owner: scoped keys, an audit log, fail-open. This page is specific on purpose — what’s live today, and what’s on the roadmap, each labeled. SOC 2 and self-host are planned, not shipped. Data residency: US (us-east-1).
Fail-open to your baseline.
The gateway is fail-open: before the first token, if Recovea is unreachable or errors, the request falls back cleanly to your provider on your own keys; mid-stream, you get a clean error to retry. One-config rollback is always available. Reliability is a feature, not a footnote.
Specific, in order of your control.
Self-host in your VPC Planned
No prompt bodies by default
Salted per-tenant cache Planned
Scoped, audited access
No training on your data
SOC 2 on the roadmap
An auditable, basis-labeled cost ledger you can defend.
Live today: scoped keys, an append-only audit log, and a hash-chained cost ledger that attributes every dollar by key, team, and lever. Verified savings — net of quality, on the IPMVP spine — are off · proof pending until the eval gate ships. Need to show your board? Finance gets the same ledger as a second lane.
- Scoped, audited: key mint/rotate/revoke is audit-logged; ledger history is hash-chained and append-only.
- Every figure drills to the request that produced it. No vanity numbers.
- IPMVP-grade when verified savings turn on — the same performance-contracting method used to verify energy savings; off · proof pending today.
When we’re not a fit
If an inline proxy is a hard no in your org, we’ll tell you we’re not a fit rather than fight it. Start with a metadata-only scan, or book a security call to talk through the deployment roadmap (self-host is planned, not shipping today).