Security & compliance

Your keys, your data

RavenGate is bring-your-own-key by design. We sit in front of your provider traffic for visibility — we don't store your provider keys in plaintext, and we don't use your traffic to train anything.

vpn_key

BYOK by default

Your OpenAI, Anthropic, Gemini, and other provider keys stay yours. RavenGate forwards requests on your behalf and never marks up or resells your token usage.

privacy_tip

PII redaction guardrails

Emails, names, phone numbers, and other personal data are redacted from requests and responses before they're written to your logs — on by default for Pro and Team plans.

storage

Configurable retention

Request logs are retained for 7 days on Free and 90 days on Pro and Team. You control how long your data is kept, and you can delete it at any time.

Compliance alignment

Built with compliance in mind

RavenGate's data handling practices are designed to align with common compliance frameworks, helping your security and legal teams move faster during review.

SOC 2

SOC 2 readiness

Infrastructure, access controls, and logging practices are built toward SOC 2 Type II readiness as we scale.

GDPR

GDPR alignment

PII redaction, configurable retention, and data deletion on request support alignment with GDPR data minimization principles.

CCPA

CCPA alignment

Customers can access, export, or delete their organization's logged data at any time to support CCPA data subject requests.

FAQ

Data handling questions

You connect your provider keys to RavenGate so it can forward requests on your behalf. Keys are encrypted at rest and are never logged, displayed in full after creation, or shared with any third party.

RavenGate logs request and response metadata (model, token counts, cost, latency) and, if enabled, request/response bodies with PII redacted. You control retention per plan and can delete logs at any time.

No. Your request and response data is used only to power your own analytics dashboard. RavenGate does not use customer traffic to train any models.

Guardrails scan request and response bodies for emails, names, phone numbers, and other personal data and replace them with placeholders before anything is written to storage. This runs automatically at the proxy layer on Pro and Team plans.

Yes. You can delete your request logs and account data at any time from your dashboard. Deletions are processed promptly across our systems.

Get started

See your traffic with confidence

Start free — no credit card required. Bring your own keys and connect in minutes.

Start free