Sécurité

What LLM EU does to protect your requests and your data, stated as controls rather than as assurances.

Transport et identifiants

Seule la rétention nulle est implémentée : les corps des prompts et des complétions ne sont pas écrits dans la base de données. Les requêtes nécessitant une rétention non nulle sont refusées, pas traitées en silence sous un autre paramètre de rétention.

Only zero retention is implemented: prompt and completion bodies are not written to the database. Traces contain metadata. Stored policy choices 24h, 7d and 30d do not enable body storage. Requests exceeding policy return 403 retention_exceeds_policy first; otherwise effective nonzero retention returns 501 retention_not_implemented.

Les régions d'endpoint décrivent une configuration, pas une géolocalisation indépendante. L'inférence simulée n'exécute aucun poids de modèle et signale dev-mock. L'inférence réelle nécessite un backend configuré pour la région de l'endpoint ; la localisation européenne et la propriété européenne sont distinctes.

Seeded endpoints are mocks: responses say dev-mock and no model weights run. Real inference requires a configured backend for each region and matching endpoints. Region rows and status are configuration, not independent geolocation. Residency filters and failover restrictions are tested; ownership classes do not imply immunity from legal disclosure.

Sous-traitants

The subprocessor inventory is incomplete. Categories are not confirmed contracted entities. Legal identities, processing locations, data categories and a review date remain pending. Sous-traitants →

Un test d'intrusion indépendant n'a pas encore été réalisé. Quand il le sera, nous publierons ici sa date, sa portée et un résumé des conclusions, et nous ne décrirons pas la plateforme comme testée avant cela.

No independent penetration test has been carried out yet. Saying otherwise would be worse than saying nothing.

Isolation and abuse

Known limitations before launch

  • Role authorization within an organization is incomplete as a full RBAC: policy, team, settings, credit and key revocation are limited to owner or admin, a platform_write key can only be minted from the console by an owner or admin, bulk exports need a writing role, and viewer is read-only. Read access to an organization's traces, usage and exports remains organization-wide. These findings are not evidence of cross-organization access.
  • Keep stripe_enabled off. When enabled, the credit handler accepts a user-submitted amount without payment verification. This is not a working card-payment integration. Backend fixes and regression tests are required before enabling payments.
  • Legal entity details, reviewed agreements and a named subprocessor inventory are unfinished. These disclosures do not establish production security readiness or certification.

Legal document readiness · Accessibilité · Preuves et vérification

Reporting

The disclosure contact is in security.txt. security.txt


LLM EU est une société privée. Ce n'est pas une institution de l'UE ni un organisme d'évaluation de la conformité à l'AI Act. « Vérifié » sur LLM EU signifie documenté, pas légalement certifié.