What happens to your data
EthosGuard is a pilot-stage platform, and this page describes its security posture honestly: what is in place today, how your content moves, and what is on the roadmap. No certification theater.
Hosting and encryption
The platform runs on managed cloud infrastructure in the United States, with a managed Postgres database. Data is encrypted in transit (TLS) and at rest, and the production database keeps point-in-time recovery for the last seven days.
Tenant isolation and access
Every evaluation is scoped to its tenant at the application layer. API keys are stored only as SHA-256 hashes, never in plain text, and every key carries its own rate limits. Dashboard access is gated per tenant.
Model providers
Evaluations are performed using Anthropic and OpenAI models. Content submitted for evaluation is sent to those providers' APIs for processing under their enterprise API terms, which by default exclude API data from model training.
Retention
Evaluations and their audit records are retained to preserve the evidence trail. For pilots, a retention window and deletion terms are agreed in the pilot scope, and tenant data is deleted on request at the end of an engagement.
What we do not do
We do not sell or share your content, do not use your data to serve other customers, and do not train models on your evaluations. The demo workspace uses synthetic sample data only.
Deployment options
Hosted single-region deployment today. Dedicated instances and alternative regions can be arranged as part of a pilot scope where data residency requires it.
On the roadmap, in the open: formal security certification, expanded audit exports, and role-based access. If your security review needs specifics beyond this page, ask, and you will get direct answers from the people who built it.
Security questions welcome
Send your security questionnaire or ask directly. Straight answers, fast.