Skip to main content
The platform’s architecture is built for workloads with strict data-handling requirements. This page explains what the technical controls give you and how to request compliance documentation. For reports or a security review, contact support@redpill.ai.
Read Trust boundary first. The gateway is attested and does not retain request bodies, but plaintext is visible to the attested gateway after TLS or E2EE decryption. Compliance posture depends on which model you use: confidential or routed.

Technical controls relevant to compliance

Regulatory requirements

The platform supports Data Processing Agreements (DPA) and, for healthcare workloads, Business Associate Agreements (BAA). Certification status (for example SOC 2 and HIPAA) changes over time; contact support@redpill.ai for current reports and scope.

Choosing a model for regulated data

  • Use a confidential model when the upstream that runs the model must be attested and the prompt must not reach a non-attested third party.
  • A routed model sends your prompt to a third-party provider that is not attested. Confirm that provider’s terms meet your requirements before using it for regulated data.

Requesting documents

For enterprise customers and prospects, the platform provides security documentation, a DPA, and (where applicable) a BAA. Contact support@redpill.ai.