Skip to main content
This page is the source of truth for what DecimalAI does with your data. For a quick scan, jump to Data we store or How to delete data.

Data we store

For each trace ingested via the SDK or API: For each manifest registered via the SDK:
Prompt and output text is stored in plaintext. If your prompts or agent outputs contain PII, credit card numbers, or other sensitive data, you must scrub it client-side before traces are sent. The SDK does not redact for you — run your own sanitizer between agent execution and decimalai.send().

What we do NOT store

  • Your LLM API keys. Pre-deploy regression checks don’t need them. The Playground stores BYOK keys encrypted at rest, scoped to the organization, never logged. Storing or removing them requires the admin role; any member of the org can spend against them.
  • Your source code. The SDK reads only SKILL.md files under the per-runtime skill directories in your project (.claude/skills/, .agents/skills/, .windsurf/skills/, and similar — see Skills for the full list). User-level directories such as ~/.claude/skills/ are opt-in via include_global=True and are not scanned by default.
  • Inbound request bodies to the platform API beyond what’s documented as an endpoint payload.

Encryption

  • At rest. All data in Postgres is encrypted at rest by Cloud SQL (Google-managed AES-256); object storage is Google Cloud Storage, encrypted at rest by default (AES-256).
  • In transit. All API traffic uses TLS 1.2+. HSTS is enabled on api.decimal.ai and app.decimal.ai.
  • Secrets. API keys are stored as SHA-256 hashes; only the prefix (dai_sk_...) is visible after creation. Every key is a secret — there is no publishable variant. BYOK LLM keys are encrypted at rest with Fernet (AES-128-CBC with an HMAC-SHA256 authentication tag) using a server-managed key.

Retention

Traces older than your retention period are deleted automatically (rolling, daily). Manifests, skills, and datasets are kept indefinitely so your version history stays intact.

How to delete data

Deletions are hard deletes — the row is removed, not soft-flagged. Backups retain deleted data for up to 7 days for disaster recovery; after that the row is unrecoverable.

Compliance

DecimalAI is not currently SOC 2 certified. The certification is in progress (target: late 2026).
For enterprise procurement reviews, we provide:
  • Detailed security questionnaire (SIG Lite, CAIQ)
  • Architecture diagram + threat model
  • Penetration test summary (available on request)
  • DPA / standard contractual clauses for EU data flows
Email hello@decimal.ai for the docs package.

Hosting region

Production runs on Google Cloud Platform (Cloud Run + Cloud SQL for PostgreSQL) in region us-central1. Enterprise customers can request a different GCP region; we’ll spin up an isolated stack and migrate.

Reporting a vulnerability

If you find a security issue, please do not open a public GitHub issue. Email hello@decimal.ai — PGP key available on request. We follow coordinated disclosure practice. We do not currently run a paid bug bounty.