Security
Security posture for pilots.
FrugalAI treats the gateway as sensitive infrastructure. Virtual keys are hashed, provider keys are encrypted, tenant cache scope is partitioned, and request records keep auditable routing receipts.
Pilot defaults
Start in monitor mode, keep prompt retention minimal, restrict owner dashboard access, and enable live routing only after customer traffic passes quality review.
Enterprise review
DPA, VPC or self-hosted deployment, retention controls, and SSO/SAML are handled through Enterprise terms.
Coordinated disclosure
We welcome good-faith security research on frugalai.io and the FrugalAI gateway. If you believe you have found a vulnerability, email security@frugalai.io with the affected endpoint or component, steps to reproduce, and the impact you observed. We acknowledge reports within 3 business days.
Safe harbor. Research conducted in good faith and within these rules is authorized. We will not refer it for prosecution or pursue claims under the CFAA or DMCA, consistent with the US Department of Justice policy on good-faith security research.
Rules. Do not access, modify, or exfiltrate data beyond the minimum needed to demonstrate the issue. Do not test against other tenants or their data; use your own account. No denial-of-service, spam, or social engineering. Give us 90 days to remediate before any public disclosure.
We do not run a paid bounty program. With your permission, we are glad to credit meaningful reports here. Our machine-readable policy lives at /.well-known/security.txt.