Skip to main content
The platform’s architecture is built for workloads with strict data-handling requirements. This page explains what the technical controls give you and how to request compliance documentation. For reports or a security review, contact support@redpill.ai.
Read Trust boundary first. The gateway is attested and does not retain request bodies, but plaintext is visible to the attested gateway after TLS or E2EE decryption. Compliance posture depends on which model you use: confidential or routed.

Technical controls relevant to compliance

ControlHow the platform provides it
Data isolationInference runs in a TEE (Intel TDX). The gateway is attested with a hardware quote.
No body retentionThe gateway stores hashes in receipts, not request or response bodies.
Verifiable processingA signed receipt binds each request and response to the attested workload.
Confidential upstreamsFor a confidential response, the upstream enclave is verified and the channel bound before forwarding, confirmed by the receipt’s upstream.verified event.
Encryption in transitTLS for all connections, with optional E2EE field-level encryption.

Regulatory requirements

RequirementHow the platform helps
Data minimization (GDPR)No request or response body retention by default.
Confidential processingTEE isolation with attestation and per-response receipts.
AuditabilityVerifiable attestation and signed receipts you can check independently.
The platform supports Data Processing Agreements (DPA) and, for healthcare workloads, Business Associate Agreements (BAA). Certification status (for example SOC 2 and HIPAA) changes over time; contact support@redpill.ai for current reports and scope.

Choosing a model for regulated data

  • Use a confidential model when the upstream that runs the model must be attested and the prompt must not reach a non-attested third party.
  • A routed model sends your prompt to a third-party provider that is not attested. Confirm that provider’s terms meet your requirements before using it for regulated data.

Requesting documents

For enterprise customers and prospects, the platform provides security documentation, a DPA, and (where applicable) a BAA. Contact support@redpill.ai.