Security & Compliance
*Last Updated: March 14, 2026*
CallStack AI Labs Co., Ltd. is committed to providing a secure, compliant, and trustworthy AI orchestration platform. This document outlines our security practices, compliance posture, and acceptable use policies.
Company Information
| Legal Entity | CallStack AI Labs Co., Ltd. |
| Address | Unit 401, Level 4, Core E, Cyberport 3, 100 Cyberport Road |
| City | Hong Kong |
| Postal Code | 999077 |
| Country/Region | Hong Kong SAR |
Security Architecture
Data Protection
- 🔐 Encryption in Transit — All API traffic is encrypted via TLS 1.3
- 🔐 Encryption at Rest — Sensitive configuration data encrypted with AES-256
- 🔐 No Data Retention — We do not store prompt content or model outputs
- 🔐 Minimal Logging — Only request metadata (timestamps, token counts) is retained for billing
- 🔐 No Training Data — Customer data is never used for model training or improvement
Access Control
- API key lifecycle management with rotation and expiry
- Role-based access control (RBAC) for team management
- SSO integration via SAML 2.0 and OIDC (Enterprise)
- IP allowlisting for network-level access control
Infrastructure Security
- Deployed on enterprise-grade cloud infrastructure
- Regular third-party penetration testing
- Automated vulnerability scanning in CI/CD pipeline
- DDoS protection and WAF at the edge
Responsible AI
CallStack AI Labs is fully committed to the principles of Responsible AI as outlined by Microsoft, Google, and Anthropic.
Content Safety
We enforce multi-layer content safety controls:
- Platform-Level Filters — Azure Content Safety integration for all routed requests
- Custom Filter Libraries — Organization-specific sensitive content rules and keyword filter lists for secondary screening
- Output Screening — Post-generation content review to catch harmful outputs
- PII Redaction — Automatic detection and masking of personally identifiable information before reaching model providers
Usage Monitoring
- Real-time monitoring for abuse patterns and anomalous usage
- Automated alerts for content safety violations
- Configurable governance policies per team, project, and model
Prohibited Uses
The following uses of our platform are strictly prohibited:
- 🚫 Generation of illegal, harmful, violent, or hateful content
- 🚫 Development of malware, exploits, or cyberattack tools
- 🚫 Fraud, phishing, social engineering, or misinformation
- 🚫 Violation of intellectual property rights or privacy
- 🚫 Generation of CSAM or non-consensual intimate imagery
- 🚫 Unauthorized access attempts or platform abuse
- 🚫 Any activity that violates applicable laws and regulations
Enforcement
| Severity | Action |
|---|---|
| Minor violation | Warning and remediation guidance |
| Moderate violation | Temporary API access suspension |
| Severe violation | Permanent account termination |
| Legal violation | Account termination and referral to authorities |
Privacy
Data We Collect
| Data Type | Purpose | Retention |
|---|---|---|
| Account information (email) | Account management | Duration of account |
| API request metadata | Billing and analytics | 90 days |
| Payment records | Financial reconciliation | As required by law |
Data We Do NOT Collect
- ❌ Prompt content or conversation history
- ❌ Model-generated outputs
- ❌ Customer business data or proprietary information
Service Level Agreement
| Metric | Starter | Professional | Enterprise |
|---|---|---|---|
| Uptime | 99.5% | 99.9% | 99.95% |
| Support response | 48h | 12h | 4h |
| Incident escalation | Email + Chat | Dedicated channel |
Compliance Certifications
CallStack AI Labs maintains compliance with:
- SOC 2 Type II — Security, availability, and confidentiality (in progress)
- GDPR — EU data protection regulation compliance
- Microsoft Responsible AI — Aligned with Microsoft's AI principles and content policies
Disclaimer
- CallStack AI Labs acts as an orchestration and governance layer; we are not responsible for the content generated by upstream model providers
- AI model outputs may contain errors; customers are responsible for validating critical information
- Service interruptions caused by force majeure or upstream provider outages are excluded from SLA coverage
Contact
For security, compliance, or privacy inquiries:
- 🏢 CallStack AI Labs Co., Ltd.
- 📍 Unit 401, Level 4, Core E, Cyberport 3, 100 Cyberport Road, Hong Kong SAR
- 📮 999077
- 📧 [email protected]
- 🌐 callaiapi.com