Security, privacy, and data handling
Architecture, encryption, data handling, subprocessors, and operational security — everything a technical buyer or security team needs to evaluate AI TokenScope.
Architecture overview
TokenScope operates as a transparent proxy between your developers and the Anthropic API. Developers authenticate via browser SSO and receive a scoped session token. The real Anthropic API key is never sent to developer machines — it is decrypted only within the proxy service when forwarding a request.
Developer
Runs tokenscope launcher · Authenticates via browser
TokenScope Proxy
Policy evaluation · Budget check · Classification · Request logging
TokenScope API + Database
Attribution · Audit trail · Reporting · Configuration
Anthropic API
Claude processes the request · Returns response
Policy applied before forwarding. Budget checks and policy evaluation happen at the proxy, before the request is sent to Anthropic. Off-scope or budget-exceeding requests are stopped at this layer.
Data stored at the API layer. Request metadata, attribution, classification results, and (if configured) prompt content are stored in the TokenScope database. Claude response content is not stored.
Hosting and infrastructure
Backend — Railway.app
- Postgres database
- Redis cache
- Proxy service
- API service
Region: US (primary)
Frontend — Vercel
- Next.js web application
- Static assets
- Global CDN delivery
Region: Global edge network
Tenant isolation
Application-level tenant scoping. Each workspace's data is isolated through tenant-aware data-access controls.
Data residency (US)
All production data is stored in the United States.
EU / regional residency
Additional data residency regions are on the Enterprise roadmap. Contact us to discuss your requirements.
Encryption
Data in transit
TLS 1.2+ enforced on all connections between clients, TokenScope, and Anthropic.
Anthropic API key at rest
AES-256 application-layer encryption. The key is decrypted only within the proxy, per request.
User passwords
Bcrypt hashing. Passwords are not recoverable.
Backup encryption
Infrastructure-level backup encryption is handled by Railway. Contact us for details during a security review.
Authentication and authorization
Google SSO
Available on all plans.
Microsoft Entra ID SSO
Available on Business plan.
Email / password
Standard password authentication with bcrypt hashing.
Role-based access control
Admin, manager, developer, finance, security reviewer, and auditor roles.
Instant access revocation
Revoke any developer's access immediately without rotating the Anthropic API key.
Session management
Browser-based sessions. Developers re-authenticate after session expiry.
SAML 2.0
Enterprise plan. On the roadmap.
SCIM provisioning
Enterprise plan. On the roadmap.
Data handling
What is stored depends on the configured storage mode and retention policy. Customer data is not used to train models and is not shared with third parties.
Full content
Request metadata and prompt text are stored per the configured retention period.
Metadata only (Privacy Mode)
Team plan or abovePrompt text is never stored. A cryptographic hash is recorded for audit continuity.
Prompt data used for training
No — customer data is not used to train any models.
Prompt data shared with third parties
No — data is not sold or shared with third parties beyond required subprocessors.
Configurable retention
30 days (Free) · 90 days (Startup) · 1 year (Team) · 2 years (Business). Custom retention on Enterprise.
Data deletion on request
Email hello@aitokenscope.com to request workspace data deletion.
See Privacy for Teams for the prompt visibility matrix and storage-mode configuration guide.
Access to customer data
Access to production systems and customer data is limited to essential operations personnel. All production access requires authentication.
For detailed information about access controls, audit logging, and privileged access management as part of a formal security review, please contact our team.
Security validation
We are transparent about our current security validation status. The items below reflect what has and has not been completed.
TLS certificate management
Managed by Railway and Vercel infrastructure.
Dependency vulnerability scanning
Automated dependency scanning in our development pipeline.
Third-party penetration test
We have not yet completed a third-party penetration test. This is on our roadmap.
SOC 2 Type II
SOC 2 certification is on our roadmap. Contact us for current status.
Security questionnaire
We respond to security questionnaires during formal security reviews. Email hello@aitokenscope.com.
To discuss security review documentation or submit a questionnaire, contact our team.
Vulnerability disclosure
If you discover a security vulnerability in AI TokenScope, please report it responsibly before public disclosure.
- Email security@aitokenscope.com with a description of the issue.
- We will acknowledge your report within 2 business days.
- We ask that you allow reasonable time for investigation and remediation before public disclosure.
- We will credit responsible reporters in our security acknowledgements where appropriate.
Security reports: security@aitokenscope.com
Subprocessors
AI TokenScope uses the following third-party providers to deliver the service. Customer data is processed only as required to provide the service.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Railway.app | Backend hosting, Postgres, Redis | Usage metadata, encrypted API keys | US |
| Vercel | Frontend hosting, CDN | Web application traffic | Global |
| Anthropic | Claude API (request forwarding) | Prompt content (forwarded per standard Anthropic processing) | US |
| Resend | Transactional email | Email addresses | US |
| Paddle | Payment processing, billing | Billing data | Global |
Last updated: July 2026. For data processing agreements, email hello@aitokenscope.com.
Need more detail for your security review?
We are happy to answer questions, provide documentation, or walk through our architecture with your security team.
Report a vulnerability: security@aitokenscope.com