Read-only, out of band, and honest about what is not in place yet.
Camaze needs less access than most tools you already run. This page describes exactly what it takes, what it collects, what it deliberately does not, and where our security program currently stands.
What access does Camaze require?
Read-only billing and usage credentials for each AI provider, and read access to cost data in your cloud accounts. Nothing that can spend money, create or change a deployment, issue requests against a model, or read prompt and completion content. Camaze sits out of band and never in the request path, so it cannot add latency to your systems or fail in a way that affects production.
What we take, and what we cannot take.
| Required | Never requested | |
|---|---|---|
| Provider access | Read-only billing and usage endpoints | Any key able to issue model requests |
| Cloud access | Read access to cost and usage reports | Any role able to create, change or delete resources |
| Content | Token counts and model identifiers | Prompt or completion content of any kind |
| Position | Out of band, reading billing data | Proxy, gateway or SDK in the request path |
| Tool admin | Read-only seat and usage reports | Ability to assign, revoke or purchase seats |
| Writes | None | Any write access to any connected system |
This is architectural, not configurable. The platform has no code path that issues a model request, modifies a deployment or authorizes a charge. Even a compromised Camaze credential cannot spend your money or alter your systems.
What is collected.
Enough to attribute and forecast cost. Nothing more.
Collected
- Spend and invoice records per provider and per period
- Usage counts: requests, input, output and cached tokens
- Model, deployment and endpoint identifiers
- API key, project, workspace and cloud tag identifiers
- Seat assignment and last-activity dates for per-seat tools
- Cloud cost and usage records for GPU compute
- Your own org structure mapping, which you provide
Not collected
- Prompt content
- Completion or response content
- Embeddings, documents or retrieval corpora
- Your customers' personal data
- Model weights, code or configuration
- Anything from inside your application runtime
Where we actually stand.
Split into what is in place today and what is planned. We would rather be checkable than impressive.
Encryption and isolation
TLS 1.2 or higher in transit, encryption at rest, and per-customer logical isolation of data. Credentials are stored in a managed secrets service and are never written to logs.
Least privilege and audit logging
Internal access is granted on a least-privilege basis and logged. Support access to a customer environment is time-bound and recorded. Administrative actions are auditable.
Role-based access for your team
Scoped access so a budget owner sees their own scope and finance sees the consolidated position. Scheduled reports inherit the recipient's permissions.
Deletion and export
Export everything at any time. On termination, credentials are revoked immediately and data is deleted within 30 days or sooner on request.
Formal certification
SOC 2 Type II is planned. We do not hold it today and we will not imply otherwise. When it is achieved, this page will state the audit period and the report will be available under NDA.
SSO, SCIM and residency
SSO and SCIM provisioning, custom roles down to individual permissions, private connectivity and regional data residency are planned and are available on Enterprise agreements on a case-by-case basis today. Ask and you will get a straight answer on timing.
For your security team.
We will complete your security questionnaire in full, including the questions where the answer is that we do not have something yet. If a control is not in place, the response will say so and give the plan rather than an evasive equivalent.
Architecture documentation, data flow diagrams, subprocessor list and our incident response process are available on request. Write to security@camaze.com.
If you find a security issue, report it to the same address. We will acknowledge within one business day and we will not pursue anyone acting in good faith.
Security questions
Do you read our prompts or completions?
No. Camaze works from usage and billing metadata: token counts, model identifiers, timestamps, keys, projects, deployments and cloud cost records. Prompt and completion content is not collected, not stored and not required for anything the platform does.
Can the platform spend money or change anything?
No. Every credential is read-only, scoped to billing and usage. Nothing Camaze holds can create a deployment, change a model configuration, issue a request against a model, or authorize a charge. This is a design constraint, not a setting.
Are you SOC 2 or ISO 27001 certified?
Not currently. We are an early company and we are not going to claim a certification we do not hold. Our security program is described on this page in enough detail for a vendor review, and we will answer a questionnaire in full.
Formal certification is planned. When it is achieved it will be stated here with the audit period and the report available under NDA, and not before.
Where is data stored?
In managed cloud infrastructure in the United States by default, encrypted at rest and in transit. Regional data residency is available on Enterprise agreements. The specific region and provider are confirmed during vendor review.
What happens if we leave?
You can export everything at any time. On termination, credentials are revoked immediately and your data is deleted within 30 days, or sooner on request. Backups age out on their own retention schedule, which is documented in the agreement.
Do you use our data to train models?
No. Your cost and usage data is used to operate the service for you. It is not used to train models, and it is not pooled into any cross-customer dataset or benchmark without an explicit, separately agreed opt-in.
Who inside your company can see our data?
Access is limited to the people who need it to operate the service and support your account, granted on a least-privilege basis and logged. Support access to a customer environment is time-bound and recorded.