Your data trains your model and nothing else
We're a small company, so here is exactly what we do with your data, where it runs and when it's deleted. We don't claim certifications we don't hold.
What we commit to in writing
Used only for your model
Your examples and logs train and test your model only. They are never pooled with other clients' data or used to train anything we sell to someone else.
No provider keys
We never ask for your OpenAI, Anthropic or Google keys. When our model is unsure it returns "defer", and your own code calls your existing provider.
Deleted when we're done
Training data is deleted within 30 days of the engagement ending, or sooner on request. You get written confirmation. Weights are handed over to you and deleted from our side if you don't host with us.
No frontier outputs in training
We don't train on GPT, Claude or Gemini outputs, which their terms restrict. Where data needs filling in, we use open models whose licences allow it.
Where your data goes
| Provider | Purpose | What it sees |
|---|---|---|
| Modal | GPU training and serving | Training data during a run; requests to your endpoint |
| Hugging Face | Downloading open base models | Nothing of yours. Downloads only. |
| Your cloud (optional) | Self-hosted deployment | Everything stays in your account |
Data in transit uses TLS. Stored data sits in encrypted volumes with access limited to the engineer on your project. For data that can't leave your environment, we work inside your cloud account instead.
What we don't have yet
We don't hold SOC 2 or ISO 27001 certification. If your security review requires them, we deploy into your own cloud account and never hold your data at all. We're happy to sign your NDA or DPA, and to fill in a security questionnaire.
Questions or a security issue to report: poojith@illate.dev.