Skip to main content
Trust Center

Security, privacy, and data handling

Architecture, encryption, data handling, subprocessors, and operational security — everything a technical buyer or security team needs to evaluate AI TokenScope.

Architecture overview

TokenScope operates as a transparent proxy between your developers and the Anthropic API. Developers authenticate via browser SSO and receive a scoped session token. The real Anthropic API key is never sent to developer machines — it is decrypted only within the proxy service when forwarding a request.

TokenScope architecture — request and data flow

Developer

Runs tokenscope launcher · Authenticates via browser

Local machine

TokenScope Proxy

Policy evaluation · Budget check · Classification · Request logging

Railway (US)

TokenScope API + Database

Attribution · Audit trail · Reporting · Configuration

Railway (US)

Anthropic API

Claude processes the request · Returns response

Anthropic infrastructure
Local (developer machine)
TokenScope-hosted (Railway)
Anthropic infrastructure

Policy applied before forwarding. Budget checks and policy evaluation happen at the proxy, before the request is sent to Anthropic. Off-scope or budget-exceeding requests are stopped at this layer.

Data stored at the API layer. Request metadata, attribution, classification results, and (if configured) prompt content are stored in the TokenScope database. Claude response content is not stored.

Hosting and infrastructure

Backend — Railway.app

  • Postgres database
  • Redis cache
  • Proxy service
  • API service

Region: US (primary)

Frontend — Vercel

  • Next.js web application
  • Static assets
  • Global CDN delivery

Region: Global edge network

Tenant isolation

Application-level tenant scoping. Each workspace's data is isolated through tenant-aware data-access controls.

Available now

Data residency (US)

All production data is stored in the United States.

Available now

EU / regional residency

Additional data residency regions are on the Enterprise roadmap. Contact us to discuss your requirements.

Planned

Encryption

Data in transit

TLS 1.2+ enforced on all connections between clients, TokenScope, and Anthropic.

Available now

Anthropic API key at rest

AES-256 application-layer encryption. The key is decrypted only within the proxy, per request.

Available now

User passwords

Bcrypt hashing. Passwords are not recoverable.

Available now

Backup encryption

Infrastructure-level backup encryption is handled by Railway. Contact us for details during a security review.

Available now

Authentication and authorization

Google SSO

Available on all plans.

Available now

Microsoft Entra ID SSO

Available on Business plan.

Available now

Email / password

Standard password authentication with bcrypt hashing.

Available now

Role-based access control

Admin, manager, developer, finance, security reviewer, and auditor roles.

Available now

Instant access revocation

Revoke any developer's access immediately without rotating the Anthropic API key.

Available now

Session management

Browser-based sessions. Developers re-authenticate after session expiry.

Available now

SAML 2.0

Enterprise plan. On the roadmap.

Planned

SCIM provisioning

Enterprise plan. On the roadmap.

Planned

Data handling

What is stored depends on the configured storage mode and retention policy. Customer data is not used to train models and is not shared with third parties.

Full content

Request metadata and prompt text are stored per the configured retention period.

Metadata only (Privacy Mode)

Team plan or above

Prompt text is never stored. A cryptographic hash is recorded for audit continuity.

Prompt data used for training

No — customer data is not used to train any models.

Available now

Prompt data shared with third parties

No — data is not sold or shared with third parties beyond required subprocessors.

Available now

Configurable retention

30 days (Free) · 90 days (Startup) · 1 year (Team) · 2 years (Business). Custom retention on Enterprise.

Available now

Data deletion on request

Email hello@aitokenscope.com to request workspace data deletion.

Available now

See Privacy for Teams for the prompt visibility matrix and storage-mode configuration guide.

Access to customer data

Access to production systems and customer data is limited to essential operations personnel. All production access requires authentication.

For detailed information about access controls, audit logging, and privileged access management as part of a formal security review, please contact our team.

Security validation

We are transparent about our current security validation status. The items below reflect what has and has not been completed.

TLS certificate management

Managed by Railway and Vercel infrastructure.

Available now

Dependency vulnerability scanning

Automated dependency scanning in our development pipeline.

Available now

Third-party penetration test

We have not yet completed a third-party penetration test. This is on our roadmap.

Planned

SOC 2 Type II

SOC 2 certification is on our roadmap. Contact us for current status.

Planned

Security questionnaire

We respond to security questionnaires during formal security reviews. Email hello@aitokenscope.com.

Available now

To discuss security review documentation or submit a questionnaire, contact our team.

Vulnerability disclosure

If you discover a security vulnerability in AI TokenScope, please report it responsibly before public disclosure.

  • Email security@aitokenscope.com with a description of the issue.
  • We will acknowledge your report within 2 business days.
  • We ask that you allow reasonable time for investigation and remediation before public disclosure.
  • We will credit responsible reporters in our security acknowledgements where appropriate.

Security reports: security@aitokenscope.com

Subprocessors

AI TokenScope uses the following third-party providers to deliver the service. Customer data is processed only as required to provide the service.

ProviderPurposeData processedRegion
Railway.appBackend hosting, Postgres, RedisUsage metadata, encrypted API keysUS
VercelFrontend hosting, CDNWeb application trafficGlobal
AnthropicClaude API (request forwarding)Prompt content (forwarded per standard Anthropic processing)US
ResendTransactional emailEmail addressesUS
PaddlePayment processing, billingBilling dataGlobal

Last updated: July 2026. For data processing agreements, email hello@aitokenscope.com.

Need more detail for your security review?

We are happy to answer questions, provide documentation, or walk through our architecture with your security team.

Report a vulnerability: security@aitokenscope.com