Security
Exactly what is true today, and how to check it yourself.
We never hold a credential that can write to your systems
Connecting Cupelio never means handing over a key that can modify anything of yours. Our ingest tokens are write-only into our own database and can do nothing else. This is an architectural commitment, not a policy: the endpoint that receives your data has no code path that could reach back out to your systems.
Encrypted in transit and at rest
Every connection to Cupelio runs over TLS. Your data is encrypted at rest on our infrastructure provider’s side, not something we bolted on.
Tenant isolation, enforced by the database
Every table is isolated by organization at the database level, using Postgres row-level security, not application code. Verified directly: two organizations, one attempting to read, write, and delete the other’s data through every path available, all attempts refused by the database itself, before the application ever runs.
Your prompts and completions are never stored
We need token counts, a model name, and who the call was for. We do not need what was said. Known content fields are stripped from what you send us before it is written to disk, and the table that holds priced usage has no column that could hold it.
Financial records cannot be edited, including by us
Once a cost or revenue event is recorded, it cannot be changed or deleted. Corrections are new rows, never edits, enforced by the database. If a number needs to change, the old number and the reason both stay on record.
What we don’t claim yet
No SOC 2. No ISO 27001. No uptime guarantee.
Questions about any of this: security@cupelio.com.