Resources

Security

Metrecept sits between your apps and upstream model providers. Exact-replay inventory is purpose-bound. Governance stays on the Pipeline System.

Security docsWaste demoProduct

Cache purpose

Identical chat completions may be stored per tenant for replay only. Purpose header: X-AT-Cache-Purpose: identical-request-replay. Opt out with cache_control: "no_store". Replay inventory is not a training corpus.

Keys & tenancy

Customer API keys are stored hashed (SHA-256) at rest. Suspended tenants receive HTTP 403. Issued prefix today is sk-at-… (Metrecept brand; rename deferred).

Receipts & honesty

Cache HITs can carry a signed X-Ohm-Receipt (Ed25519) verifiable against the public JWKS directory. Non-goals are published at GET /v1/public/honesty so marketing cannot outrun the pipe.

Subprocessors

Model providers you enable, AWS (host), Stripe (billing), Amplify (marketing site). Details and legal: Legal & compliance, DPA, Privacy.

Report an issue

Operational questions: Support. Enterprise security review or BAA-style conversations: Contact.

All resources →