Security & data handling

What we do with your data, stated plainly

Metering is a financial function, so it should be boring and inspectable. Here is exactly which controls exist today, what our defaults are, and what you should ask us for.

This page is maintained by the MetricAI team to answer common security and privacy questions about the product. It describes controls that exist in the platform today. It is not an independent audit, a certification, or a legal warranty. Where we are not yet certified, we say so rather than implying otherwise.

Controls in the product today

Bring your own keys (BYOK)

You connect your own provider credentials. MetricAI uses them to route and meter your calls; they are stored encrypted and are never shown back to you in full after entry. Revoke or rotate a key at any time from the dashboard.

Prompt & output retention is off by default

Metering does not require prompt or completion content. Storing prompts and storing outputs are separate opt-in switches under Settings → Data & Privacy. With both off, we retain metadata only: timestamps, model, provider, token counts, latency, cost, and attribution IDs.

Log retention windows

Request logs are retained for 7 days on Developer and 90 days on Startup. Enterprise retention is configurable, including shorter windows. Retention applies to whatever you have chosen to store.

Access control

Workspace members authenticate individually. API keys are scoped to a workspace, displayed once at creation, and stored masked afterwards; they can be revoked or regenerated at any time. Role-based access control is available on Enterprise.

Transport security

All API and dashboard traffic is served over HTTPS/TLS. Provider credentials and API keys are encrypted at rest.

Budget and blast-radius controls

Hard budget caps refuse calls once a limit is reached rather than recording the overspend after the fact. Caps can be scoped per workspace, agent, or user.

Shared responsibility

Who is responsible for what

MetricAI

Runs the metering layer, ledger, and dashboard. Keeps your keys encrypted, honours your retention settings, and ships the controls described above.

Your AI providers

Handle model inference and apply their own data-use and retention policies to the content you send. Review their terms alongside ours.

You

Decide what content is sent through the SDK, whether prompts and outputs are stored, who has workspace access, and how keys are rotated.

Available on request

We would rather send you a document we can defend than publish a badge we cannot. Ask and we will respond with specifics.

Data processing agreement (DPA)

Available on request for paid plans. Contact us and we will send the current version for your legal review.

Data residency

Tell us your residency requirement and we will confirm in writing what we can support for your workload before you commit.

Subprocessor list

We maintain a current list of infrastructure and payment subprocessors and will share it on request.

Security questionnaires & procurement review

We complete customer security questionnaires. Send yours and we will return it with evidence for each answer we can support.

Support SLA

Community support on Developer, email support on Startup, and a contractual SLA negotiated per agreement on Enterprise.

Report a vulnerability

Email us with steps to reproduce. We acknowledge reports within two business days and will not pursue action against good-faith research.

security@metricai.co.in

Incident contact

For a suspected incident affecting your workspace, email the security address above and copy support. Live service state is on the status page.