We sit in your production path.
That is a serious thing to ask of you. Everything a security reviewer normally has to extract through a questionnaire is answered on this page instead.
The questions that decide it
These are the ones that stop a deal when they go unanswered. No procurement form required.
What happens to our provider keys?
LogRite holds your provider credential envelope-encrypted, storing only the last four characters for identification. Your developers get a relay key instead, so the real key never reaches an application, and nobody can quietly route around the policy by using it directly.
Do we have to send you our logs?
No. Keep your evidence in LogRite if that is easiest, or send it to the Splunk or Datadog you already run. Rule sets also export as files you can version in your own repository, so your policy is never trapped in our platform.
How quickly are we told about an incident?
Within 72 hours of a confirmed breach. We run documented incident response procedures and rehearse them with regular tabletop exercises rather than only writing them down.
Sensitive data stays in
Inspected before it leaves, masked before it's stored
Card numbers, SSNs, passwords, and tokens are masked at the code level before a log is ever written. And every routed AI call can be inspected in real time — allowed, flagged, or blocked — so PII never leaves unseen.
AI Warden is a pre-adoption capability; the panel illustrates the control surface, not customer results.
POST api.model-provider.com/v1/chat
{ prompt: "Summarize ticket for card 4242 4242 4242 4242 …" }
SOC 2 Type II
Independently audited and certified for security, availability, and confidentiality.
End-to-End Encryption
TLS 1.3 for data in transit, AES-256 encryption for data at rest.
GDPR & HIPAA
Compliant with major data protection regulations worldwide.
99.9% Uptime SLA
Redundant infrastructure across multiple availability zones.
Comprehensive Security Measures
Multi-layered protection for your data at every stage
Swipe for more →
Sensitive data, handled differently
Traditional logging captures whatever the code happens to write — and worries about sensitive data after it is already stored. LogRite acts at the code level, before the incident.
Our Security Practices
Employee Security
- Mandatory security awareness training for all employees
- Strict access controls with regular audits
- Non-disclosure agreements and security policies
- Immediate access revocation upon employee departure
Incident Response
- 24/7 security operations center monitoring
- Documented incident response procedures
- Customer notification within 72 hours of confirmed breach
- Regular incident response drills and tabletop exercises
Vulnerability Management
- Regular penetration testing by third-party security firms
- Automated vulnerability scanning and patch management
- Bug bounty program for responsible disclosure
- Regular security code reviews and static analysis
Data Protection
- Automatic PII and sensitive data detection
- Data retention policies aligned with your requirements
- Secure data destruction procedures
- Regular backups with tested recovery procedures
Responsible Disclosure
We value the security research community and welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue in our platform, please report it to us.
What to Include
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact and severity assessment
- Any proof-of-concept code or screenshots
Our Commitment
- We will acknowledge receipt within 24 hours
- We will provide regular updates on our investigation
- We will credit researchers who report valid vulnerabilities (if desired)
- We will not pursue legal action against researchers who follow responsible disclosure guidelines