Read Trust boundary first. The gateway is attested and does not
retain request bodies, but plaintext is visible to the attested gateway after TLS or E2EE decryption.
Compliance posture depends on which model you use: confidential or routed.
Technical controls relevant to compliance
Regulatory requirements
The platform supports Data Processing Agreements (DPA) and, for healthcare workloads, Business Associate
Agreements (BAA). Certification status (for example SOC 2 and HIPAA) changes over time; contact
support@redpill.ai for current reports and scope.
Choosing a model for regulated data
- Use a confidential model when the upstream that runs the model must be attested and the prompt must not reach a non-attested third party.
- A routed model sends your prompt to a third-party provider that is not attested. Confirm that provider’s terms meet your requirements before using it for regulated data.