Trimio is the proxy layer between your applications and 1,600+ AI models — every request passes through it. Every control on this page exists because of that position: encrypted in transit, processed in memory, never used for training. A SOC 2 audit is underway; every document lands here first.
Both audits are with an independent CPA firm. Reports are shared under NDA — request access and we'll deliver them the day they're issued.
Point-in-time audit of control design. Fieldwork is in progress.
Operating effectiveness over an observation window. Follows Type I completion.
The controls behind the audit, grouped the way the report groups them. Continuously monitored — this page reflects current status.
TLS on every connection; stored credentials encrypted at rest and scoped to your workspace.
Request and response bodies are processed in memory and not stored by default — only the metadata that powers your dashboard is kept. Never used for training.
Role-scoped access with MFA internally; customer-side virtual keys rotate and revoke instantly without touching provider credentials.
Any issue on Trimio's side routes requests straight to your provider. Continuous health checks, 99.99% uptime SLA.
40+ metadata fields per request — cost, tokens, latency, routing decision — searchable and exportable for your own audits.
Security reports acknowledged within one business day, with updates through the fix. Disclosure process below.
Model providers receive traffic only for the models you route to them — the effective list mirrors your routing configuration.
No. Request and response bodies are processed in memory for optimization and discarded — zero stored by default. What we keep is metadata: tokens, cost, latency, model, cache status — the fields that power your dashboard.
Never — ours or anyone else's. Traffic routes to your providers under your own keys and agreements; Trimio adds no training use on top.
Trimio is fail-open: any issue on our side routes requests straight to your provider, transparently and automatically. 99.99% uptime SLA with ~20ms proxy overhead when active.
Bring-your-own-key by default. Stored credentials are encrypted at rest and scoped to your workspace; your teams use virtual keys that rotate and revoke instantly without touching provider credentials.
Infrastructure runs on Google Cloud in the United States. Model providers receive traffic only for the models you route to them — the effective subprocessor list mirrors your routing configuration.
Request access on this page. Both Type I and Type II are with an independent CPA firm; reports are shared under NDA and delivered the day they're issued.
Email security@trimio.ai. We acknowledge within one business day and keep you posted through the fix.
Request the SOC 2 report, or put your security team in a room with ours.