Skip to content
Security

Your training logs contain your IP. We treat them that way.

Denpex is built to keep your proprietary model architectures, training data samples, and internal research inside your control. Below is the short, honest version. For SOC 2 status, sub-processors, and the full control set, visit our Trust Center.

What we do. And what we don't.

Concrete controls, not vague promises. We label compliance honestly: SOC 2 Type II is planned, not claimed.

PII / PHI masking

Client-side masking runs on the agent before any log is transmitted. Default patterns catch emails, SSNs, phone numbers, credit cards, and common PHI (MRN, NPI). Add your own patterns. Raw PII/PHI never leaves your cluster.

Logs deleted after diagnosis on Free and Team

On Free and Team, raw logs are processed in memory and never written to durable storage. We retain anonymized failure signatures and resolution metadata only, never raw lines. An in-VPC agent (no log egress at all) ships on Scale and Data Center.

🔒

Encryption

TLS 1.3 in transit, AES-256 at rest. Encryption keys are customer-managed (BYOK) on Data Center via your KMS.

Compliance

SOC 2 Type II planned. GDPR DPA available, HIPAA BAA available on Data Center. Sub-processor list and data flow on the Trust Center.

Access controls

SSO via Google, Discord, GitHub, and Microsoft. Enterprise SAML/OIDC SSO is on our roadmap. Role-based access (owner, admin, member, viewer) on Team+. 30-day audit log of all billing and team changes.

Deployment options

Cloud (default), single-tenant on AWS / Azure / GCP, or fully air-gapped on your hardware on Data Center. White-label / OEM available for GPU clouds.

Sub-processors

Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes.

Cloudflare
Hosting, edge network, KV, D1, Workers, R2
Global edge (data stored in your selected region)
SOC 2 Type II, ISO 27001, PCI DSS
Stripe
Payment processing and subscription management
US, EU (by customer selection)
PCI DSS Level 1, SOC 2 Type II, ISO 27001
SendGrid (Twilio)
Transactional email (signups, alerts, contact replies)
US, EU (region selectable)
SOC 2 Type II, ISO 27001, HIPAA-eligible
LLMZONE / LLM Provider
AI-powered log analysis and failure diagnosis (training logs may contain hostnames, paths, and environment details)
US, EU (provider-dependent)
SOC 2 Type II (provider-dependent)
PostHog
Product analytics (opt-in via cookie consent)
US, EU
SOC 2 Type II
GitHub
Source code hosting, CI/CD, issue tracking
US (data in your selected region)
SOC 2 Type II, ISO 27001
Slack (optional)
Alert delivery when customer configures Slack as a channel
US
SOC 2 Type II, ISO 27001, FedRAMP Moderate
PagerDuty (optional)
Incident routing when customer configures PagerDuty as a channel
US, EU
SOC 2 Type II, ISO 27001, HIPAA
Twilio (optional)
SMS / iMessage alert delivery when customer configures it
US, EU
SOC 2 Type II, ISO 27001, HIPAA-eligible
Certifications listed are each sub-processor's own attestations (vendor-attested), not Denpex certifications.
We give 30 days' notice before adding a new sub-processor via email and the changelog RSS feed. Customers may object in writing; if we cannot resolve the concern you may terminate the affected services for a pro-rated refund.

Request a document

Need our DPA, BAA, SOC 2 report, or pen-test summary? We'll send it under NDA.

We respond within one business day. Documents are sent under NDA via DocuSign.