What we do with your data, stated plainly
Metering is a financial function, so it should be boring and inspectable. Here is exactly which controls exist today, what our defaults are, and what you should ask us for.
This page is maintained by the MetricAI team to answer common security and privacy questions about the product. It describes controls that exist in the platform today. It is not an independent audit, a certification, or a legal warranty. Where we are not yet certified, we say so rather than implying otherwise.
Controls in the product today
Bring your own keys (BYOK)
You connect your own provider credentials. MetricAI uses them to route and meter your calls; they are stored encrypted and are never shown back to you in full after entry. Revoke or rotate a key at any time from the dashboard.
Prompt & output retention is off by default
Metering does not require prompt or completion content. Storing prompts and storing outputs are separate opt-in switches under Settings → Data & Privacy. With both off, we retain metadata only: timestamps, model, provider, token counts, latency, cost, and attribution IDs.
Log retention windows
Request logs are retained for 7 days on Developer and 90 days on Startup. Enterprise retention is configurable, including shorter windows. Retention applies to whatever you have chosen to store.
Access control
Workspace members authenticate individually. API keys are scoped to a workspace, displayed once at creation, and stored masked afterwards; they can be revoked or regenerated at any time. Role-based access control is available on Enterprise.
Transport security
All API and dashboard traffic is served over HTTPS/TLS. Provider credentials and API keys are encrypted at rest.
Budget and blast-radius controls
Hard budget caps refuse calls once a limit is reached rather than recording the overspend after the fact. Caps can be scoped per workspace, agent, or user.
Who is responsible for what
Runs the metering layer, ledger, and dashboard. Keeps your keys encrypted, honours your retention settings, and ships the controls described above.
Handle model inference and apply their own data-use and retention policies to the content you send. Review their terms alongside ours.
Decide what content is sent through the SDK, whether prompts and outputs are stored, who has workspace access, and how keys are rotated.
Available on request
We would rather send you a document we can defend than publish a badge we cannot. Ask and we will respond with specifics.
Available on request for paid plans. Contact us and we will send the current version for your legal review.
Tell us your residency requirement and we will confirm in writing what we can support for your workload before you commit.
We maintain a current list of infrastructure and payment subprocessors and will share it on request.
We complete customer security questionnaires. Send yours and we will return it with evidence for each answer we can support.
Community support on Developer, email support on Startup, and a contractual SLA negotiated per agreement on Enterprise.
Report a vulnerability
Email us with steps to reproduce. We acknowledge reports within two business days and will not pursue action against good-faith research.
security@metricai.co.inIncident contact
For a suspected incident affecting your workspace, email the security address above and copy support. Live service state is on the status page.
