Last updated: June 22, 2026
Security is foundational to how we build Subconscious. We treat customer data with the utmost care and hold ourselves to strict security standards across our infrastructure, processes, and vendor relationships.
We do not store, log, or retain the content of your inference requests or responses. Your prompts, completions, and any data passed through them are processed transiently to serve your request and are not persisted by us.
The only data we retain about your usage is token-accounting metadata required to operate and bill the service:
This metadata records how much you used — never what you sent or received. We have no record of the substance of your queries.
All traffic to and from our platform and inference endpoints is encrypted in transit using industry-standard TLS. Inference requests are routed directly to our hosting provider's gateway over encrypted connections.
Access to the platform is authenticated and scoped to your organization. API keys are issued per organization, can be revoked at any time, and are required for every inference request. Internal access to production systems is restricted to authorized personnel on a least-privilege basis.
We build on a small set of established, security-conscious infrastructure providers. Each subprocessor is selected for its security posture and maintains its own compliance program. See our Subprocessors page for the full list and links to their trust centers.
If you believe you have found a security vulnerability, we want to hear from you. Please report it to security@subconscious.dev. We will investigate all legitimate reports and work to address confirmed issues promptly. We ask that you give us reasonable time to remediate before any public disclosure.
For questions about our security practices or to request additional documentation, contact security@subconscious.dev.