UsageTap Trust Center

Trust is built with clear boundaries, not borrowed badges.

UsageTap handles the usage and cost signals behind AI products. This page explains what we collect, how we protect it, who helps us operate the service, and where our security program stands today.

01

Collect deliberately

Meter is metadata-first. Content processing belongs to explicit features.

02

Limit access

Identity, organization membership, and least-privilege service roles gate data.

03

Explain the gaps

We state what is certified, what is not, and whose assurance applies.

Data boundaries

The product you use determines the data we need.

We do not describe every UsageTap feature as “metadata-only” when that is not true. Meter, Compress, and Gateway have different jobs and therefore different processing boundaries.

Metadata-firstMETER

Usage without prompt content

Meter records the commercial and operational facts needed to understand usage, enforce plans, and calculate cost.

  • Customer and feature identifiers, usage units, model, token counts, timing, status, and estimated cost.
  • Prompts, model responses, tool payloads, request headers, and provider API keys are not part of standard Meter telemetry.
Explicit content processingCOMPRESS

Content only when you ask us to transform it

Compress must receive the content selected for compression, review, or quality evaluation in order to return a result.

  • Only the submitted or policy-selected content is processed for the requested operation.
  • Trials and production sampling use explicit retention controls; retained production samples expire automatically.
Configured routingGATEWAY

Requests pass through to the selected model provider

Gateway receives model requests so it can enforce usage policy, route them, and return the provider response.

  • Requests may be sent to OpenAI, Anthropic, Google, or OpenRouter based on your configured route.
  • Bring-your-own-provider credentials are stored as encrypted secrets and kept out of browser-visible configuration.

Security controls

Concrete safeguards in the product today.

These controls are implemented in our current AWS architecture. They are not a claim of independent certification.

Shared responsibility matters

AWS secures the underlying cloud. UsageTap remains responsible for how we configure, operate, and secure the application built on it.

Tenant-scoped access

Dashboard access is tied to server-managed organization memberships. Short-lived identity claims and server-side checks keep one customer from requesting another customer's records.

Encryption by default

Customer data is encrypted in transit and at rest on AWS. Sensitive integration credentials use AWS Secrets Manager and dedicated, rotating AWS KMS keys.

Credentials stay server-side

API keys and provider credentials are redacted after saving and made available only to the backend functions that need them. Public and embedded sessions use short-lived signed tokens.

Deliberate data collection

Meter is designed for usage metadata, not prompt or response content. Features that must process content, such as Compress or Gateway, make that boundary explicit.

Operational monitoring

AWS CloudWatch metrics, logs, dashboards, and alarms help us identify failures and unusual operating conditions. Production function logs have a defined retention period.

Recoverable infrastructure

Production stateful resources use retention safeguards and point-in-time recovery where supported. Critical background work uses encrypted queues, retry controls, and failure alarms.

Service providers

The platforms behind UsageTap.

We rely on specialized providers instead of attempting to build cloud infrastructure, payment processing, analytics, or consent management from scratch.

See how providers fit into our Privacy Policy

Primary cloud infrastructure

Amazon Web Services

AWS

Hosts our application, identity, APIs, databases, object storage, email delivery, encryption, and operational monitoring.

AWS SOC 1, SOC 2, and SOC 3 information

UsageTap subscription billing

Stripe

Stripe

Runs our hosted checkout and customer billing flows. Stripe handles payment card details; UsageTap does not store full card numbers.

Stripe security and compliance

Product and website analytics

PostHog

PostHog

Helps us understand product adoption and website performance so we can improve the experience and diagnose issues.

PostHog Trust Center

Consent and legal policy tooling

Termly

Termly

Powers our cookie consent controls and the published Privacy Policy and Terms of Service experiences.

Termly compliance and security

Feature-dependent providers

Some connections are chosen by you.

Model providers

OpenAI, Anthropic, Google, or OpenRouter when selected for Gateway or model-powered processing.

Customer integrations

Stripe for customer billing synchronization and Slack for alerts, only when an organization connects them.

Compliance roadmap

Where we are, and what comes next.

For an early, founder-led company, the honest answer is more useful than a wall of grey badges.

Now

Published transparency

Document current controls, data boundaries, providers, legal documents, and known gaps in one place.

Next

Formalize the control program

Turn implemented safeguards into owned policies, recurring evidence, access reviews, incident procedures, and vendor reviews.

Later

Independent assurance

Pursue independent certification when customer requirements and company maturity make the scope and investment appropriate.

A question we have not answered?

Ask us directly. We will tell you what is true today.

Contact UsageTap