Security at Leanroute

What we protect, and how.

You're trusting Leanroute with API keys, prompts, and billing data. The short version: Singapore-hosted, TLS 1.2+ everywhere, BYOK keys encrypted with a master held only in runtime memory, per-org cache isolation, and an active disclosure channel. The long version — regulatory regimes, sub-processors, controls — lives on /compliance.

Reporting a vulnerability

Please report suspected security issues to [email protected]. We acknowledge within one business day and target a triage decision within five. PGP is available on request.

We commit to safe-harbor for good-faith research that respects our disclosure policy: no denial-of-service, no data exfiltration beyond proof-of-concept, no accessing other customers' data, and give us reasonable time to fix before public disclosure (default 90 days).

Formal reference: /.well-known/security.txt (RFC 9116).

Certifications & attestations

Leanroute is not currently SOC 2, ISO 27001, or HIPAA-attested. The roadmap below is honest — no badges displayed until the attestation is signed. If you need something before then, we can meet a security questionnaire (SIG Lite / CAIQ) and sign an interim DPA with SCCs.

AttestationStatus
SOC 2 Type I
Planned — Q3 2026
Vendor selection in progress (Vanta / Drata / Secureframe).
SOC 2 Type II
Planned — Q1 2027
Follows Type I after the six-month observation window.
ISO 27001
Not yet
On the roadmap post-SOC-2. Available on request for enterprise deals earlier.
PDPA (Singapore)
Aligned at launch
Data residency in Singapore. See /compliance for details.

Third-party security review

External scrutiny catches what internal review misses. Our current posture:

External penetration test
Scheduled — Q4 2026

Independent review by a boutique application-security firm. Report summary published here once landed.

Coordinated disclosure program
Planned — post-launch

Public program on HackerOne or Intigriti with a modest bounty pool. Timeline: within 90 days of GA.

Continuous automated review
Live

Dependabot on every repo, secret scanning enabled, npm audit on CI, Semgrep on pull requests.

What's in place today

TLS 1.2+ end-to-end

Every hop encrypted — browser to gateway, gateway to every upstream provider, internal service to service.

BYOK keys encrypted

Provider keys wrapped with AES-256-GCM under a runtime-only master. A leaked DB dump is useless without the master.

Per-org cache isolation

Cache keys namespaced by org id — a hit from one org can't satisfy a request from another. No cross-tenant leakage path.

Hard spend + rate caps

Daily and monthly spend caps + per-key RPM/TPM throttling. Runaway loops hit the wall before an upstream call is made.

Full control list, sub-processors, and residency detail on /compliance.

Enterprise procurement

We handle security questionnaires (SIG Lite / CAIQ), sign DPAs with EU Standard Contractual Clauses, and can walk you through the request-flow diagram on a call. Email [email protected] with what you need — response within one business day.

[email protected]Compliance posturePrivacy policyTermssecurity.txt