AIRoute
Initial security posture

No-prompt by default.

AIRoute's first commercial motion is a metadata-only control audit. That means the initial review is designed around billing records, usage exports, request counts, token counts, model names, app labels, sensitivity labels, latency, errors, and retries, not raw prompt or output content.

Data requested first

  • Provider invoices and usage exports
  • Model, token, request, cost, and timestamp fields
  • API-key, app, workflow, or endpoint labels
  • Sensitivity, data-class, or policy labels when available
  • Latency, status, retry, and error metadata when available

Data not needed first

  • Raw prompts
  • Model outputs
  • Customer records
  • Provider API keys
  • Production payload capture

Routing posture

No production rerouting should happen during the first audit. Observe mode comes later, and controlled routing only follows customer-approved benchmark evidence and sensitivity policy for approved workloads.

Implementation direction

Future observe-mode instrumentation should use an OpenAI-compatible gateway with prompt/output capture disabled by default, configurable retention, explicit workload tags, customer-controlled sensitivity labels, and clear audit receipts for any benchmark or routing recommendation.

This is an initial product posture, not a completed SOC 2 program. The point of phase one is to reduce the trust ask enough to get real usage metadata and prove whether meaningful savings and data-exposure controls exist.

Request audit