SECURITY

Security and safety controls around every UVOX route.

UVOX publishes credential, logging, tenant-isolation, engine-mode and fallback practices while keeping proprietary routing algorithms confidential.

Encrypted credentials

Stored provider credentials are encrypted at rest and are never displayed again after saving.

Revocable gateway keys

Create separate UVOX keys for devices, applications and environments, then revoke them independently.

Limited logging

Normal request logs focus on operational, route, fallback and usage data rather than prompt or generated-answer bodies.

Tenant separation

Customer accounts, keys, limits, logs and billing records are separated by tenant.

Protected account access

Secure password handling, verification flows and session controls protect customer and owner accounts.

Operational safeguards

Rate limits, error handling, per-tenant engine controls, provider switches, fallback reasons, emergency Zero-Loss rollback, backups and audit records support production reliability.

What we disclose

Credential handling, account controls, data practices, engine modes, protected-content categories, fallback behaviour, service status and customer responsibilities.

Combined Engine safety boundaries

Auto and Maximum Savings may omit historical context. System and developer instructions and recent messages are preserved. Selected relevant tool definitions remain unchanged. Exact-copy, structured-output, tool-history and configured high-risk requests use complete-context fallback. Zero-Loss Cache preserves complete request content.

What remains confidential

Engine algorithms, internal routing decisions, optimisation logic, proprietary verification methods and detailed architecture.

Security questions and responsible disclosures can be sent to info@uvox.tech.

Review UVOX before production.

Test with your own non-sensitive workload and contact us for commercial security documentation.

Contact UVOX

What “zero-risk” means at UVOX

Zero-risk applies specifically to Zero-Loss Cache Mode.

No prompt changes

No prompt rewriting or context deletion. Provider-supported cache metadata may be added separately.

No response substitution

No semantic answer cache or reuse of an old generated response. The selected model produces a fresh response.

No model/provider switching

The provider and model in the customer request remain selected throughout the generation path.

Independent proof

SHA-256 hashes, provider response IDs, usage and downloadable evidence let customers test the claim themselves.

Important: the complete HTTP payload is not claimed to be byte-for-byte identical because provider-native cache metadata may be added. Prompt content remains unchanged.

Run a zero-risk proof