Your training logs contain your IP. We treat them that way.
Denpex is built to keep your proprietary model architectures, training data samples, and internal research inside your control. Below is the short, honest version. For SOC 2 status, sub-processors, and the full control set, visit our Trust Center.
What we do. And what we don't.
Concrete controls, not vague promises. We label compliance honestly: SOC 2 Type II is planned, not claimed.
PII / PHI masking
Client-side masking runs on the agent before any log is transmitted. Default patterns catch emails, SSNs, phone numbers, credit cards, and common PHI (MRN, NPI). Add your own patterns. Raw PII/PHI never leaves your cluster.
Logs deleted after diagnosis on Free and Team
On Free and Team, raw logs are processed in memory and never written to durable storage. We retain anonymized failure signatures and resolution metadata only, never raw lines. An in-VPC agent (no log egress at all) ships on Scale and Data Center.
Encryption
TLS 1.3 in transit, AES-256 at rest. Data Center customers can supply a data key for diagnosis logs. Denpex wraps it with a key-encryption key held as a Worker secret, and can decrypt while the key is active. This is not customer-held KMS custody.
Compliance
SOC 2 Type II planned. GDPR DPA available, HIPAA BAA available on Data Center. Sub-processor list and data flow on the Trust Center.
Access controls
SSO via Google, Discord, GitHub, and Microsoft. Enterprise SAML/OIDC SSO is on our roadmap. Role-based access (owner, admin, member, viewer) on Team+. 30-day audit log of all billing and team changes.
Deployment options
Cloud (default) or single-tenant on AWS / Azure / GCP. Logs can be diagnosed entirely inside your network with DENPEX_LOCAL=1: the deterministic engine runs on-host and nothing leaves the cluster. A fully self-hosted control plane is on our roadmap, not available today. White-label / OEM available for GPU clouds.
Sub-processors
Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes.
| Sub-processor | Purpose | Data region | Vendor-attested certifications |
|---|---|---|---|
| Cloudflare | Hosting, edge network, KV, D1, Workers, R2, transactional email delivery, and anonymous Turnstile abuse verification | Global edge (data stored in your selected region) | SOC 2 Type II, ISO 27001, PCI DSS |
| Stripe | Payment processing and subscription management | US, EU (by customer selection) | PCI DSS Level 1, SOC 2 Type II, ISO 27001 |
| SendGrid (Twilio) | Transactional email (signups, alerts, contact replies) | US, EU (region selectable) | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Google (Gemini, OAuth, Search, YouTube) | Primary AI log analysis via the Denpex proxy (training logs may contain hostnames, paths, and environment details); authentication identifiers; and log-derived search queries sent to Google Search or YouTube when those optional research paths are used | Provider-dependent | Vendor-attested; scope varies by service |
| Anthropic (Claude) | AI-powered log analysis and failure diagnosis, fallback model path via the Denpex proxy when the primary model is rate-limited | US | SOC 2 Type II |
| DeepSeek | AI-powered log analysis, secondary fallback when the primary proxy is exhausted | Provider-dependent | Vendor-attested (provider-dependent) |
| Groq | AI-powered log analysis, optional fallback provider | Provider-dependent | Vendor-attested; review the configured service terms |
| TokenHub | AI-powered log analysis, optional fallback routing service | Provider-dependent | Vendor-attested; review the configured service terms |
| PostHog | Product analytics (opt-in via cookie consent) | US, EU | SOC 2 Type II |
| GitHub | Source code hosting, CI/CD, issue tracking, and optional issue research using log-derived query text | US (data in your selected region) | SOC 2 Type II, ISO 27001 |
| Slack (optional) | Alert delivery when customer configures Slack as a channel | US | SOC 2 Type II, ISO 27001, FedRAMP Moderate |
| PagerDuty (optional) | Incident routing when customer configures PagerDuty as a channel | US, EU | SOC 2 Type II, ISO 27001, HIPAA |
| Vonage / Nexmo (optional) | SMS alert delivery, preferred SMS provider when configured | US, EU | Vendor-attested |
| Twilio (optional) | SMS / iMessage alert delivery, fallback SMS provider when Vonage is not configured | US, EU | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Stack Exchange | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Algolia (Hacker News search) | Optional Hacker News index search using log-derived query text | Provider-dependent | Vendor-attested |
| Y Combinator (Hacker News) | Optional community-result retrieval using log-derived query text | Provider-dependent | Vendor-attested |
| Lobsters | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Optional community search using log-derived query text | Provider-dependent | Vendor-attested | |
| DEV Community (Forem) | Optional developer-community search using log-derived query text | Provider-dependent | Vendor-attested |
| GitLab | Optional issue and code search using log-derived query text | Provider-dependent | Vendor-attested |
| Exa | Optional web research using log-derived query text | Provider-dependent | Vendor-attested |
| OpenCode | Optional developer research using log-derived query text | Provider-dependent | Vendor-attested |
| Discord | Optional community-result retrieval and linked attachment delivery | Provider-dependent | Vendor-attested |
Request a document
Need our DPA, BAA, SOC 2 report, or pen-test summary? We'll send it under NDA.