Security
We secure every request to the router
Kumo is an independent routing layer with its own infrastructure in front of the model providers. Every request that touches our endpoints is encrypted and protected — and inference itself happens at upstream providers, under their own policies. This page draws that line clearly, so you always know what is protected and by whom
Responsibility boundary
What we control — and what we don’t
Security you can trust starts with an honest scope. Here is exactly where Kumo’s guarantees apply
Our zone: the route and the infrastructure
- Every endpoint is served over TLS 1.2+ — requests to the Kumo router are encrypted end to end on our side
- Stored metadata and secrets are encrypted at rest with AES-256
- API keys are hashed at rest, shown once at creation, and revocable at any time
- Prompt and completion bodies are not retained — we keep only billing and usage metadata
- Routing runs on our own infrastructure, so a degraded provider doesn’t take your traffic down with it
The providers’ zone: model inference
- To serve a request, your prompt is forwarded to the single upstream provider that serves the model you called — each model card in the catalog names that provider
- Provider-side processing is governed by each provider’s own policies and terms — not by Kumo’s
- We do not control, and cannot take responsibility for, how providers handle content on their side
- That is exactly why we recommend the usage practices below: they keep you safe regardless of any provider’s posture
Own infrastructure
Independent routing, stable quality
Kumo runs its own routing infrastructure on direct, committed lab contracts — we don’t rent someone else’s proxy. That independence is what turns a volatile provider market into a stable service for you
Our own routing layer
Requests are routed by infrastructure we build and operate ourselves. No third-party middleman between your app and our router
One audited provider per model
Every model in the catalog names the provider actually serving it — no silent swaps to a cheaper lookalike, and the card tells you which upstream you’re on
Predictable failure shape
When an upstream errors, you get an explicit, contract-shaped 502 instead of a hung request — so your existing retry logic can rerun the call or switch models without guesswork
Quality despite the market
Provider markets fluctuate; your experience shouldn’t. Independent routing lets us hold quality steady regardless of any single supplier’s state
Posture at a glance
How we protect your data
| Control | Status | Detail |
|---|---|---|
| Encryption in transit | Live | TLS 1.2+ on every request to Kumo endpoints |
| Encryption at rest | Live | AES-256 for stored metadata and secrets |
| Prompt content logging | None | Only billing/usage metadata is retained by Kumo |
| API key storage | Live | Hashed at rest; shown once at creation; revocable |
| Training on your data by Kumo | Never | Kumo never uses prompts or completions to train anything |
| Provider-side processing | Provider scope | Governed by each upstream provider’s own policies — outside Kumo’s guarantees |
Safe usage
How to get the most out of Kumo, safely
Kumo is built for development and production workloads. Because inference runs at upstream providers, a little data hygiene keeps you fully in control:
Keep confidential data out of prompts
Secrets, personal and regulated data don’t belong in prompt bodies. We protect the route — but provider-side processing is beyond our control, so the safest prompt is one with nothing sensitive in it
Guard your API keys
Keep keys in environment variables, never in code or repositories. Rotate them regularly and revoke anything you no longer use — revocation is instant
Call Kumo from your server only
Never ship a Kumo key in client-side code, mobile apps or browser bundles. Proxy requests through your backend so the key never leaves your infrastructure
Build and ship with confidence
Development, staging, production — Kumo is made for real workloads. Pair it with the practices above and you get top routing quality without widening your risk surface
Questions about how we handle your data?
We answer security questions directly — usually within one business day