Security

Built to keep enterprise AI traffic private

Airia sits in the network path between your agents and the LLM vendors. Here is exactly what we do with the data we see, and what we do not do.

Controls

Four layers of protection for AI traffic

Encryption in Transit

All traffic between your agents and the Airia endpoint travels over TLS 1.3. Connections are refused at lower protocol versions. Vendor calls from Airia to OpenAI, Anthropic, and others also run over TLS.

Tenant Isolation

Each customer account runs in an isolated namespace. No request data, policy configuration, or cost record is readable from another tenant's namespace. API keys are scoped to a single account and cannot cross namespace boundaries.

PII Masking at the Edge

The policy engine scans prompt content before forwarding to any vendor. Credit card numbers, social security numbers, email addresses, and phone numbers are detected and replaced with type placeholders. Your policy rules determine which patterns trigger masking for your specific data model.

Access Controls per Team

API keys are issued per team namespace. Admin roles can revoke any team key from the dashboard without downtime. Audit logs show which key made which requests, when, and to which vendor. Enterprise plans support SSO and SAML for identity-provider-managed access.

Data Handling

What Airia stores and for how long

Airia processes request metadata (timestamp, team namespace, vendor, model, token count, latency, response code) to power the cost and observability dashboard. Prompt content and model responses are not stored by default. Airia forwards each request to the target LLM vendor and discards the content.

If you enable request logging on the Teams or Enterprise plan for debugging purposes, prompt and response content is retained for 30 days and then permanently deleted. You can disable logging at any time from the dashboard. Retention periods are configurable on Enterprise.

Request metadata for billing and cost attribution is retained for 13 months to support annual finance reporting cycles. You can request a full export of your metadata at any time via the dashboard or by emailing [email protected].

Airia does not sell your data, does not use customer requests to train or fine-tune models, and does not share data with third parties outside the LLM routing path. For Enterprise customers on VPC or on-premises deployment, the control plane runs entirely inside your infrastructure and nothing leaves your network perimeter.

Questions about our data practices? Contact us and we will schedule a technical review with the engineering team.

Need a security review before signing?

We schedule direct calls with our engineering team. Bring your security questionnaire.