Skip to main content
This page is the source of truth for what DecimalAI does with your data. For a quick scan, jump to Data we store or How to delete data.

Data we store

For each trace ingested via the SDK or API: For each manifest registered via the SDK:
Prompt and output text is stored in plaintext. If your prompts or agent outputs contain PII, credit card numbers, or other sensitive data, you must scrub it client-side before traces are sent. The SDK does not redact for you — run your own sanitizer between agent execution and decimalai.send().

What we do NOT store

  • Your LLM API keys. Pre-deploy regression checks don’t need them. The Playground stores BYOK keys encrypted at rest, scoped to the workspace, never logged.
  • Your source code. The SDK never reads files outside the SKILL.md auto-discovery paths (.claude/skills/, .agents/skills/).
  • Inbound request bodies to the platform API beyond what’s documented as an endpoint payload.

Encryption

  • At rest. All data in Postgres is encrypted at rest by Cloud SQL (Google-managed AES-256); object storage is Google Cloud Storage, encrypted at rest by default (AES-256).
  • In transit. All API traffic uses TLS 1.2+. HSTS is enabled on api.decimal.ai and app.decimal.ai.
  • Secrets. API keys are stored as SHA-256 hashes; only the prefix (dai_sk_..., or dai_pk_... for a public key) is visible after creation. BYOK LLM keys are encrypted at rest with Fernet (AES-128-CBC with an HMAC-SHA256 authentication tag) using a server-managed key.

Retention

Traces older than your retention period are deleted automatically (rolling, daily). Manifests, skills, and datasets are kept indefinitely so your version history stays intact.

How to delete data

Deletions are hard deletes — the row is removed, not soft-flagged. Backups retain deleted data for up to 30 days for disaster recovery; after that the row is unrecoverable.

Compliance

DecimalAI is not currently SOC 2 certified. The certification is in progress (target: late 2026).
For enterprise procurement reviews, we provide:
  • Detailed security questionnaire (SIG Lite, CAIQ)
  • Architecture diagram + threat model
  • Penetration test summary (available on request)
  • DPA / standard contractual clauses for EU data flows
Email security@decimal.ai for the docs package.

Hosting region

Production runs on Google Cloud Platform (Cloud Run + Cloud SQL for PostgreSQL) in region us-central1 (project decimalai-prod). Enterprise customers can request a different GCP region; we’ll spin up an isolated stack and migrate.

Reporting a vulnerability

If you find a security issue, please do not open a public GitHub issue. Email security@decimal.ai — PGP key available on request. We respond to security reports within 24 hours and follow coordinated disclosure practice. We do not currently run a paid bug bounty.