Zero Data Retention
Token Factory’s zero data retention (ZDR) policy means prompt and generation data are not logged or stored persistently by default, without explicit user opt-in. Corvex retains operational metadata, such as token counts, to deliver the service. Prompt and generation data exist in volatile memory for the duration of a request. If prompt caching is active, some prompt data and associated key-value (KV) caches can remain in volatile memory for several minutes.Technical Safeguards
- Device security: Access to sensitive Corvex systems requires approved, secured devices and strong authentication.
- Network protection: Firewalls and security groups restrict inbound and outbound traffic. DDoS protections help maintain availability across core services.
- Monitoring and detection: Real-time monitoring and anomaly detection alert our team to suspicious activity.
- Vulnerability management: Ongoing vulnerability scanning and patching help identify and address known security risks.
Operational Security
- Security testing: Regular penetration testing evaluates security controls and identifies areas for remediation.
- Incident response: A documented response plan guides investigation, containment, remediation, and customer notification when required.
- Employee access: Production access is limited to authorized personnel who need it for their work. Access permissions are reviewed periodically.
- Vendor review: Vendors and subprocessors undergo security due diligence and are subject to contractual security obligations.