Your training logs contain your IP. We treat them that way.
Denpex is built to keep your proprietary model architectures, training data samples, and internal research inside your control. Below is the short, honest version. For SOC 2 status, sub-processors, and the full control set, visit our Trust Center.
What we do. And what we don't.
Concrete controls, not vague promises. We label compliance honestly: SOC 2 Type II is planned, not claimed.
PII / PHI masking
Client-side masking runs on the agent before any log is transmitted. Default patterns catch emails, SSNs, phone numbers, credit cards, and common PHI (MRN, NPI). Add your own patterns. Raw PII/PHI never leaves your cluster.
Logs deleted after diagnosis on Free and Team
On Free and Team, raw logs are processed in memory and never written to durable storage. We retain anonymized failure signatures and resolution metadata only, never raw lines. An in-VPC agent (no log egress at all) ships on Scale and Data Center.
Encryption
TLS 1.3 in transit, AES-256 at rest. Encryption keys are customer-managed (BYOK) on Data Center via your KMS.
Compliance
SOC 2 Type II planned. GDPR DPA available, HIPAA BAA available on Data Center. Sub-processor list and data flow on the Trust Center.
Access controls
SSO via Google, Discord, GitHub, and Microsoft. Enterprise SAML/OIDC SSO is on our roadmap. Role-based access (owner, admin, member, viewer) on Team+. 30-day audit log of all billing and team changes.
Deployment options
Cloud (default), single-tenant on AWS / Azure / GCP, or fully air-gapped on your hardware on Data Center. White-label / OEM available for GPU clouds.
Sub-processors
Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes.
Request a document
Need our DPA, BAA, SOC 2 report, or pen-test summary? We'll send it under NDA.