> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corvex.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Security and Zero Data Retention for Inference

> Learn how Corvex Token Factory handles inference data, retains operational metadata, and protects its systems through technical and operational controls.

Corvex Token Factory processes open-weight model inference requests. This page
explains how request content and operational metadata are handled and how
Corvex protects the systems that process them. For security
documentation and audit reports, visit the [Corvex Trust Center](https://trust.corvex.ai/).

## Zero Data Retention

Token Factory's zero data retention (ZDR) policy means prompt and generation data
are not logged or stored persistently by default, without explicit user opt-in.
Corvex retains operational metadata, such as token counts, to deliver the service.

Prompt and generation data exist in volatile memory for the duration of a
request. If prompt caching is active, some prompt data and associated key-value
(KV) caches can remain in volatile memory for several minutes.

## Technical Safeguards

* **Device security:** Access to sensitive Corvex systems requires approved,
  secured devices and strong authentication.
* **Network protection:** Firewalls and security groups restrict inbound and
  outbound traffic. DDoS protections help maintain availability across core
  services.
* **Monitoring and detection:** Real-time monitoring and anomaly detection
  alert our team to suspicious activity.
* **Vulnerability management:** Ongoing vulnerability scanning and patching
  help identify and address known security risks.

## Operational Security

* **Security testing:** Regular penetration testing evaluates security controls
  and identifies areas for remediation.
* **Incident response:** A documented response plan guides investigation,
  containment, remediation, and customer notification when required.
* **Employee access:** Production access is limited to authorized personnel
  who need it for their work. Access permissions are reviewed periodically.
* **Vendor review:** Vendors and subprocessors undergo security due diligence
  and are subject to contractual security obligations.

## Compliance and Security Review

Corvex provides security documentation and audit reports to support customer
security and compliance assessments. Visit the
[Corvex Trust Center](https://trust.corvex.ai/) for current reports and details
of their scope. For requirements specific to your use of Token Factory,
contact [Token Factory support](/reference/faq#how-do-i-contact-support).
