Security & data handling

Zero retention is architecture, not a checkbox.

This page is written for vendor reviews: what we store, where compute runs, who our sub-processors are, and what we will sign.

data handling
prompts & completionsvolatile memory only — never persisted
training on your datanever
retained metadatatimestamps, token counts, status, prices
metadata retention13 months (billing evidence), then deleted
end-user identifiersnot received, not stored
swap / core dumps on GPU nodedisabled
where compute runs
edge (TLS, routing)Hetzner — Germany, EU
GPU inferenceVerda — Finland, EU (provider-owned datacenters)
US cloud in the stacknone
data leaving EU/EEAnever
transport encryptionTLS 1.2+ end to end
technical measures

Network

Layered firewalls at host and provider level; only public-facing services are exposed. Management interfaces are not reachable from the internet.

Access

Key-based administrative access only, passwords disabled, automated brute-force protection. Access limited to the operator; secrets never in version control.

Monitoring

Infrastructure metrics only — uptime, latency, token counts. No request content in any metric, log or dashboard. Public live status: llmtech.eu/status.

sub-processors
ProviderRoleLocationContent access
Hetzner Online GmbHedge serverGermany (EU)none — content in RAM under our control
Verda (ex-DataCrunch)GPU node rentalFinland (EU)none — hardware rental, no logical access

No other processor touches request data. Analytics, error trackers, CDNs of any kind: none.

what we sign

A Data Processing Agreement under Art. 28 GDPR is ready to sign — it covers the zero-retention processing described above, the sub-processor list, breach notification within 48 hours, and audit rights. Request it at artem@llmtech.eu — happy to adapt wording to your template.

We are a small company and honest about certifications: no SOC 2 audit yet. Everything above is verifiable — ask and we will show the configuration.