Service endingThe LLM Tech API stops on 31 October 2026. Keys stop working on 1 November 2026, 00:00 UTC. Our quantized models stay on Hugging Face: huggingface.co/llmtech
Security & data handling

Zero retention is architecture, not a checkbox.

This page is written for vendor reviews: what we store, where compute runs, who our sub-processors are, and what we will sign.

data handling
prompts & completionsvolatile memory only — never persisted
training on your datanever
retained metadatatimestamps, token counts, status, latency, prices, key id, source IP
metadata retention13 months (billing evidence), then deleted
platform end-user identifiersnot received, not stored
swap / core dumps on GPU nodedisabled

The source IP we record is the address that opened the connection, which for a platform is its gateway rather than an end user. It is personal data under the GDPR, so we name it here rather than leave you to find it: it is kept for abuse prevention, on the same 13-month schedule as the rest of the billing evidence.

where compute runs
edge (TLS, routing)Hetzner — Germany, EU
GPU inferenceSeeweb — Italy, EU. The node runs in Frosinone, at a site certified to ISO 27001, 27017 and 27018.
US cloud in the stacknone
data leaving EU/EEAnever
transport encryptionTLS 1.3 only, to the edge
edge to GPU nodeWireGuard tunnel; the GPU port accepts nothing else
technical measures

Network

Layered firewalls at host and provider level; only public-facing services are exposed. Management interfaces are not reachable from the internet.

Access

Key-based administrative access only, passwords disabled, automated brute-force protection. Access limited to the operator; secrets never in version control.

Monitoring

Infrastructure metrics only — uptime, latency, token counts. No request content in any metric, log or dashboard. Public live status: llmtech.eu/status.

sub-processors
ProviderRoleLocationContent access
Hetzner Online GmbHedge serverGermany (EU)none — content in RAM under our control
Seeweb S.r.l.GPU virtual machine rentalItaly (EU)Seeweb's default account on the machine has been locked since 20 September 2026; only our keys can log in, and no hypervisor guest agent runs. The machine is virtual, so hypervisor-level access to memory cannot be excluded technically. Today that is addressed by Seeweb's general terms and its ISO 27001, 27017 and 27018 certification; an Art. 28 agreement with Seeweb was requested on 26 September 2026 and is not signed yet.

No other processor touches request data. Analytics, error trackers, CDNs of any kind: none.

what we sign

A Data Processing Agreement under Art. 28 GDPR is ready to sign — it covers the zero-retention processing described above, the sub-processor list, breach notification within 24 hours, and audit rights. Request it at artem@llmtech.eu — happy to adapt wording to your template.

We are a small company and honest about certifications: no SOC 2 audit yet. Everything above is verifiable — ask and we will show the configuration.

Last updated: 30 September 2026