TOKEN BOAT / 2026

SECURITY / TRUST

EN / GLOBAL

HOW DATA MOVESTHROUGH THEGATEWAY.

From API keys and request routing to provider processing, logs, and incident response, this page describes the service's current security boundaries.

  1. 01Your service
  2. 02Token Boat gateway
  3. 03Selected model provider
  4. 04Response returned
01

TRUST NOTE

Identity & keys

API requests use a Bearer key. Keep keys server-side. Available sign-in and second-factor methods depend on current system configuration.

02

TRUST NOTE

Requests & providers

The gateway sends the request content required for the selected model call to the corresponding upstream provider. Changing models may also change the data processor.

03

TRUST NOTE

Logs & diagnosis

The console can expose request, usage, and error diagnostics. Retention depends on data type, account status, legal duties, and security needs.

04

TRUST NOTE

Incident response

The public status page shows only configured monitors. Diagnose account-level failures with a Request ID and request logs.

05

TRUST NOTE

Privacy boundary

Do not submit personal data, credentials, or sensitive business content unless required. The privacy policy and terms govern information handling.

06

TRUST NOTE

Access control

Separate and rotate API keys by application. Available 2FA, passkey, and permission controls depend on current account configuration. Do not share privileged accounts.

07

TRUST NOTE

Data minimization

Submit only what a task requires. Remove, redact, or de-identify personal data, credentials, regulated data, and sensitive business information before use.

08

TRUST NOTE

Retention & deletion

Logs and billing records serve different purposes. Data that is no longer needed is deleted, anonymized, or restricted as applicable.

09

TRUST NOTE

Verifiable assurance

Security certifications and assurances are displayed only when supported by publishable evidence. Report suspected issues through support or the published support email.