Security
Last reviewed: August 25, 2026
IQ Routing handles two of the more sensitive data classes a buyer cares about: the prompts that leave the building, and the provider keys that pay for them. Each control below carries its status before the description: what is in force for every org, and what is available only on request.
Live today
Encryption Live today
Provider keys are encrypted at rest under authenticated encryption on every path. The per-request credential store the gateway reads on each routed call uses Fernet authenticated encryption (AES-128-CBC with an HMAC integrity tag); the row is decrypted once per request and the cleartext key is never serialised back to disk and never reaches React state outside the upload modal. The key-vault reveal path, which lets an operator recover a key through a step-up-authenticated flow, uses AES-256-GCM envelope encryption keyed off a master key that is held in secret storage outside the application, injected at runtime, and excluded from the gateway's process logs by design. Every connection between the gateway and its own storage runs over TLS, and none of that storage is reachable from the public internet; it is only addressable from inside the gateway's private network.
Audit log Live today
Every state-changing mutation across orgs, teams, providers, keys, alerts, trial grants, and ERP connections writes a row into your org's audit log with the user identifier, the action name, the prior state, the new state, and a timestamp. The log is append-only in the dashboard: there is no edit or delete action exposed for a row. Each row is also hash-chained to the one before it using a key IQ Routing holds, so an edit or a deletion in the middle of the history breaks the chain and the verifier reports where. The chain alone cannot show that the most recent rows were removed, and it does not protect against someone who holds the key; the daily external copy that would close both gaps is not switched on yet. CSV export streams uncapped via cursor pagination so a 90-day export cannot abort mid-stream.
Authentication Live today
Production sign-in runs on a dedicated managed identity provider, which issues the session and manages credentials. That identity is carried into the gateway over an HMAC-verified trust boundary, which is designed to prevent a session from being forged on the way across. The signed iq.active_org cookie carries the active-org selection; tampering invalidates the cookie.
Access enumeration mask Live today
Every admin endpoint returns 404 rather than 403 for resources outside the caller's org. The mask prevents an attacker from probing org IDs via the API surface. Every org-scoped admin endpoint calls the same membership check, which applies the mask.
Per-statement query timeouts Live today
Every storage call from the critical-path admin endpoints carries a per-statement timeout (one to ten seconds depending on the endpoint's expected work). A slow query cannot starve the connection pool or hold a transaction open long enough to block other requests.
Zero data retention Live today
Zero Data Retention is an org-level setting on every plan, including Free, with an enablement timestamp stamped server-side when you turn it on. With it on, payload logging is locked off, an attempt to arm payload capture is rejected, and any free-text reasoning generated internally while routing a request is kept out of telemetry. Two short-term stores still hold content: cached responses, with a numeric fingerprint (embedding) of the prompt used to match repeats, for up to seven days by default, and stateful conversation turns, for up to 24 hours after the last turn. An org-level erasure also deletes the conversation turns as it runs; any it misses expire within 24 hours of the last turn. Cached responses expire within seven days. Operational metadata is retained for billing and the requests browser; when loop detection is enabled, additional fingerprints, activity counts, loop flags and estimated wasted cost are kept to detect agents stuck in repeated loops. The authoritative version of this boundary, written for a security reviewer, is on the security documentation page.
SOC2 evidence pack Live today
Enterprise owners and admins generate the pack on demand from the Audit pane in the dashboard. The export builds a ZIP from the append-only audit log, with the chain-of-custody columns intact, so your own auditor can re-verify the chain offline. This is evidence-pack tooling for your audit: IQ Routing has not completed a SOC 2 audit and has no SOC 2 report. This pack is tooling for your own auditor. Questions? Email support@iq-routing.com.
Gateway PII redaction Pilot, by request
A per-org PII redaction setting can mask four kinds of identifier in message text before a request is sent to an upstream provider: email addresses, phone numbers, US Social Security numbers and payment card numbers. It is off for every organization by default, it cannot be switched on from the dashboard, and no customer has used it yet: if you need it, contact us and we will enable it for your organization and verify it with you. It does not scan tool-call arguments, attached documents or images, it is not a HIPAA Safe Harbor de-identification control, and it will not catch every identifier a prompt can carry. Treat upstream providers as recipients of whatever the setting does not mask. Do not send protected health information (PHI) through IQ Routing: IQ Routing is not a HIPAA business associate and does not sign a BAA. Send other regulated personal data only if your organization has a data processing addendum with us and its own controls in place.
Reporting a vulnerability
Email security issues to security@iq-routing.com. We acknowledge within one business day and triage within five. Our machine-readable disclosure policy is published at /.well-known/security.txt.