Skip to content
Security

Your training logs contain your IP. We treat them that way.

Denpex is built to keep your proprietary model architectures, training data samples, and internal research inside your control. Below is the short, honest version. For SOC 2 status, sub-processors, and the full control set, visit our Trust Center.

What we do. And what we don't.

Concrete controls, not vague promises. We label compliance honestly: SOC 2 Type II is planned, not claimed.

PII / PHI masking

Client-side masking runs on the agent before any log is transmitted. Default patterns catch emails, SSNs, phone numbers, credit cards, and common PHI (MRN, NPI). Add your own patterns. Raw PII/PHI never leaves your cluster.

Logs deleted after diagnosis on Free and Team

On Free and Team, raw logs are processed in memory and never written to durable storage. We retain anonymized failure signatures and resolution metadata only, never raw lines. An in-VPC agent (no log egress at all) ships on Scale and Data Center.

Encryption

TLS 1.3 in transit, AES-256 at rest. Data Center customers can supply a data key for diagnosis logs. Denpex wraps it with a key-encryption key held as a Worker secret, and can decrypt while the key is active. This is not customer-held KMS custody.

Compliance

SOC 2 Type II planned. GDPR DPA available, HIPAA BAA available on Data Center. Sub-processor list and data flow on the Trust Center.

Access controls

SSO via Google, Discord, GitHub, and Microsoft. Enterprise SAML/OIDC SSO is on our roadmap. Role-based access (owner, admin, member, viewer) on Team+. 30-day audit log of all billing and team changes.

Deployment options

Cloud (default) or single-tenant on AWS / Azure / GCP. Logs can be diagnosed entirely inside your network with DENPEX_LOCAL=1: the deterministic engine runs on-host and nothing leaves the cluster. A fully self-hosted control plane is on our roadmap, not available today. White-label / OEM available for GPU clouds.

Sub-processors

Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes.

Denpex sub-processors, with the purpose of each, the region its data is held in, and the certifications that vendor attests to.
Sub-processorPurposeData regionVendor-attested certifications
CloudflareHosting, edge network, KV, D1, Workers, R2, transactional email delivery, and anonymous Turnstile abuse verificationGlobal edge (data stored in your selected region)SOC 2 Type II, ISO 27001, PCI DSS
StripePayment processing and subscription managementUS, EU (by customer selection)PCI DSS Level 1, SOC 2 Type II, ISO 27001
SendGrid (Twilio)Transactional email (signups, alerts, contact replies)US, EU (region selectable)SOC 2 Type II, ISO 27001, HIPAA-eligible
Google (Gemini, OAuth, Search, YouTube)Primary AI log analysis via the Denpex proxy (training logs may contain hostnames, paths, and environment details); authentication identifiers; and log-derived search queries sent to Google Search or YouTube when those optional research paths are usedProvider-dependentVendor-attested; scope varies by service
Anthropic (Claude)AI-powered log analysis and failure diagnosis, fallback model path via the Denpex proxy when the primary model is rate-limitedUSSOC 2 Type II
DeepSeekAI-powered log analysis, secondary fallback when the primary proxy is exhaustedProvider-dependentVendor-attested (provider-dependent)
GroqAI-powered log analysis, optional fallback providerProvider-dependentVendor-attested; review the configured service terms
TokenHubAI-powered log analysis, optional fallback routing serviceProvider-dependentVendor-attested; review the configured service terms
PostHogProduct analytics (opt-in via cookie consent)US, EUSOC 2 Type II
GitHubSource code hosting, CI/CD, issue tracking, and optional issue research using log-derived query textUS (data in your selected region)SOC 2 Type II, ISO 27001
Slack (optional)Alert delivery when customer configures Slack as a channelUSSOC 2 Type II, ISO 27001, FedRAMP Moderate
PagerDuty (optional)Incident routing when customer configures PagerDuty as a channelUS, EUSOC 2 Type II, ISO 27001, HIPAA
Vonage / Nexmo (optional)SMS alert delivery, preferred SMS provider when configuredUS, EUVendor-attested
Twilio (optional)SMS / iMessage alert delivery, fallback SMS provider when Vonage is not configuredUS, EUSOC 2 Type II, ISO 27001, HIPAA-eligible
Stack ExchangeOptional community search using log-derived query textProvider-dependentVendor-attested
Algolia (Hacker News search)Optional Hacker News index search using log-derived query textProvider-dependentVendor-attested
Y Combinator (Hacker News)Optional community-result retrieval using log-derived query textProvider-dependentVendor-attested
LobstersOptional community search using log-derived query textProvider-dependentVendor-attested
RedditOptional community search using log-derived query textProvider-dependentVendor-attested
DEV Community (Forem)Optional developer-community search using log-derived query textProvider-dependentVendor-attested
GitLabOptional issue and code search using log-derived query textProvider-dependentVendor-attested
ExaOptional web research using log-derived query textProvider-dependentVendor-attested
OpenCodeOptional developer research using log-derived query textProvider-dependentVendor-attested
DiscordOptional community-result retrieval and linked attachment deliveryProvider-dependentVendor-attested
Certifications listed are each sub-processor's own attestations (vendor-attested), not Denpex certifications.
We give 30 days' notice before adding a new sub-processor via email and the changelog RSS feed. Customers may object in writing; if we cannot resolve the concern you may terminate the affected services for a pro-rated refund.

Request a document

Need our DPA, BAA, SOC 2 report, or pen-test summary? We'll send it under NDA.

We respond within one business day. Documents are sent under NDA and signed electronically.