Security at Leanroute
What we protect, and how.
You're trusting Leanroute with API keys, prompts, and billing data. The short version: Singapore-hosted, TLS 1.2+ everywhere, BYOK keys encrypted with a master held only in runtime memory, per-org cache isolation, and an active disclosure channel. The long version — regulatory regimes, sub-processors, controls — lives on /compliance.
Reporting a vulnerability
Please report suspected security issues to [email protected]. We acknowledge within one business day and target a triage decision within five. PGP is available on request.
We commit to safe-harbor for good-faith research that respects our disclosure policy: no denial-of-service, no data exfiltration beyond proof-of-concept, no accessing other customers' data, and give us reasonable time to fix before public disclosure (default 90 days).
Formal reference: /.well-known/security.txt (RFC 9116).
Certifications & attestations
Leanroute is not currently SOC 2, ISO 27001, or HIPAA-attested. The roadmap below is honest — no badges displayed until the attestation is signed. If you need something before then, we can meet a security questionnaire (SIG Lite / CAIQ) and sign an interim DPA with SCCs.
| Attestation | Status |
|---|---|
| SOC 2 Type I | Planned — Q3 2026 Vendor selection in progress (Vanta / Drata / Secureframe). |
| SOC 2 Type II | Planned — Q1 2027 Follows Type I after the six-month observation window. |
| ISO 27001 | Not yet On the roadmap post-SOC-2. Available on request for enterprise deals earlier. |
| PDPA (Singapore) | Aligned at launch Data residency in Singapore. See /compliance for details. |
Third-party security review
External scrutiny catches what internal review misses. Our current posture:
Independent review by a boutique application-security firm. Report summary published here once landed.
Public program on HackerOne or Intigriti with a modest bounty pool. Timeline: within 90 days of GA.
Dependabot on every repo, secret scanning enabled, npm audit on CI, Semgrep on pull requests.
What's in place today
Every hop encrypted — browser to gateway, gateway to every upstream provider, internal service to service.
Provider keys wrapped with AES-256-GCM under a runtime-only master. A leaked DB dump is useless without the master.
Cache keys namespaced by org id — a hit from one org can't satisfy a request from another. No cross-tenant leakage path.
Daily and monthly spend caps + per-key RPM/TPM throttling. Runaway loops hit the wall before an upstream call is made.
Full control list, sub-processors, and residency detail on /compliance.
Enterprise procurement
We handle security questionnaires (SIG Lite / CAIQ), sign DPAs with EU Standard Contractual Clauses, and can walk you through the request-flow diagram on a call. Email [email protected] with what you need — response within one business day.