anoman
Sign InGet API Key
Compliance

Your customer's legal team is asking about your data handling. Answer with proof.

UU PDP obligations don't wait for you to build a security program. Anoman routes every AI call through its Jakarta-hosted gateway, masks PII before it reaches any model, and returns a verifiable evidence block you can hand to a reviewer — no compliance team required.

Compliance is where AI projects quietly stall.

  • An enterprise customer's legal team sends a data-processing questionnaire — and you can't say where the data goes or what protects it.
  • UU PDP puts you on a 72-hour breach-notification clock and grants your users access, correction, and deletion rights you have no process for.
  • The moment you call a foreign model, personal data crosses a border — a transfer you can't evidence or control.
  • A reviewer asks “prove what happened on this request.” You have logs of the API call, but nothing about the guardrails or PII handling.

Anoman turns each of these into a control that runs — and is recorded — on every single call.

Compliance, enforced not promised

Three controls on every request

01

Disclosed processing regions

Account data and logs are stored in Jakarta (subprocessors listed on the privacy page), where the gateway runs. A request crosses a border only if the model you pick is processed elsewhere — surfaced on the model page, never silently.

02

PII masked before the model

NIK/KTP, NRIC, emails, and credit cards are detected and masked on every request before any provider sees them — the technical safeguard UU PDP expects, applied automatically. Phone, IP, and URL detection are available on request.

03

Evidence on every response

Each call returns an _anoman block (region, guardrail results, routing, cost) and is captured to an audit log you can export — your answer to any review.

Founding 50 · limited seats0% token markup99.9% uptime targetFaithfulness AUC 0.97 EN / 0.999 IDReceipts on every call
121,676
AI calls guarded
1,972
injections blocked
14,028
PII entities masked
See the live Trust Summary →

331,119 AI calls · 892.7M tokens since May 2026

The plan compliance teams pick

Full guardrails on a Jakarta-hosted gateway, from Rp 499rb/mo

ProMOST POPULAR
Rp 499rb /mo
  • All models — Budget, Mid, Premium & frontier
  • Monthly allowance: ~250M tokens (lean) → ~1M (frontier: Opus, GPT-Astra)
  • Batch routing (50% off)
Get Started

Start free, no credit card. OpenAI-compatible — two lines in, two lines out. No lock-in. Enterprise reviews and DPAs handled directly.

See full pricing →

Southeast Asia

Built for Southeast Asia — Rupiah billing, Bahasa guardrails

Global gateways bill in USD, moderate in English, and process your data overseas. Anoman bills in Rupiah (VA, QRIS, e-wallet, card), runs Bahasa-aware guardrails, and runs its gateway in Jakarta — hundreds of models, one OpenAI-compatible endpoint.

Global AI tools weren't built for how you actually operate.

  • Foreign gateways only take USD cards — and Indonesian cards fail their international 3DS checks. A whole “jasa bayar” market exists just to top them up.
  • English-only moderation misses Bahasa Indonesia prompt injections and unsafe content aimed at your users.
  • Your customers' data is processed overseas the moment you call a US model — hard to square with UU PDP.
  • Support and docs assume a US context, in a US timezone, in a currency you don't bill in.

Anoman is built here — Rupiah billing, Bahasa guardrails, and a Jakarta-hosted gateway on every call.

Local by default

Every call through a Jakarta-hosted gateway

01

Pay in Rupiah

Top up with VA, QRIS, e-wallet, or card — no foreign card, no third-party top-up service. 0% token markup; you pay the provider's rate.

02

Bahasa-aware guardrails

Prompt-injection detection (an ML model) checks Bahasa Indonesia prompts as well as English ones, and content moderation uses Indonesian as well as English keyword and phrase lists.

03

Gateway in Jakarta

The gateway stores account data and logs in Jakarta (subprocessors listed on the privacy page), masks PII (NIK/KTP included) before any model, and keeps a UU PDP-ready evidence trail. Each model's processing region is shown on its page.

Compliance questions, answered

Grounded in what the gateway actually enforces.

Does using Anoman make me “UU PDP compliant”?

Anoman is UU PDP-ready by design — it provides the technical safeguards (residency, PII masking, evidence) the law expects. Compliance is broader than any one vendor: you still own your notices, consent, and processes. We make the AI-data-handling part provable.

Where is my data processed and stored?

Account data and logs are stored in Jakarta (subprocessors listed on the privacy page), where the gateway runs. A request only crosses a border if the model you choose is processed elsewhere — shown on that model's page. Cross-region writes are treated as critical bugs.

Can I produce an audit trail for a review?

Yes. Every response carries a machine-readable evidence block, and calls are captured to an audit log you can export — so you can show exactly what data went to which model, and which guardrails ran.

How do you handle data-subject requests and breaches?

Anoman never trains on your data, and guarded models' providers never train on it either; the may-train community lane is opt-in; cache is partitioned per customer. For breaches, UU PDP's 3×24-hour notification applies. We handle enterprise security reviews, DPAs, and questionnaires directly — contact us.

Do you have SOC 2 or ISO 27001?

Formal certification is planned. In the meantime we handle enterprise security reviews and vendor questionnaires directly, and every call already returns evidence of the controls applied.

Can I really pay in Rupiah?

Yes — top up via Virtual Account, QRIS, e-wallet (GoPay, OVO, DANA, ShopeePay, LinkAja), or card, all in IDR. No foreign card needed and no third-party top-up service.

Do the guardrails understand Bahasa Indonesia?

Yes. Prompt-injection detection (an ML model) checks prompts written in Bahasa Indonesia as well as English. Content moderation is keyword- and phrase-based, with Indonesian and English lists.

Where is my data processed?

Account data and logs are stored in Jakarta (subprocessors listed on the privacy page), where the gateway runs. A request only crosses a border if the model you choose is processed elsewhere — shown on that model's page. By default, pattern-based PII redaction masks NIK/KTP numbers, card numbers, Singapore NRIC, Malaysian MyKad, Thai ID numbers and email addresses before a request is sent; phone numbers, URLs and IP addresses are optional per policy group. Names are not redacted.

Is there lock-in?

No. Anoman is OpenAI-compatible — two lines of config to come in, two to leave. No proprietary SDK.

Why trust a newer, Indonesia-based vendor?

Every response returns a verifiable receipt of what we did, we run a public status page and the Founding 50 program, and Anoman is built by security experts with more than 15 years in enterprise cybersecurity.

Make “is your AI compliant?” an easy question to answer.

Jakarta-hosted gateway, PII masked and evidenced on every call.