Trust & Security
Trust is the foundation of every AI infrastructure decision. This page outlines Anoman's commitments to data sovereignty, reliability, and transparency for every customer.
TRUST SUMMARY
How Anoman keeps your customers' data secure & governed
Every AI request that runs through Anoman — a guarded LLM gateway — is screened by its guardrails; faithfulness scoring is opt-in. These numbers are live counts of all AI calls guarded through Anoman, including our own teams' internal use.
- GATEWAY & DATA STORAGE
- Jakarta, ID
- FRAMEWORK
- UU PDP
- GATEWAY STATUS
- Operational
- TRAILING WINDOW
- 90 days
CONTROLS IN EFFECT
331,078 AI calls · 892.3M tokens since May 2026
Always-on guarantees
- Account data & logs stored in Jakarta (subprocessors listed on the privacy page); each model's processing region disclosed
- Guarded models never train on your prompts & completions (the may-train community lane is opt-in)
- Every response carries an _anoman evidence block
- API keys hashed; cache partitioned per customer
THE SIGNATURE
Trust here is instrumented, not asserted.
Every response Anoman produces carries this evidence block. The controls above aren't a claim on a page — they're recorded on each individual call.
{
"_anoman": {
"guardrails": {
"injection": { "status": "pass" },
"pii": { "status": "pass", "mode": "redact", "entities_processed": 0, "entity_details": [] },
"content": { "status": "pass" },
"policy": { "status": "pass" }
},
"routing": { "mode": "realtime", "region": "id", "provider_type": "cloud_direct", "provider_region": "US" },
"cache": { "hit": false, "type": "none" },
"weighted_tokens": 1240,
"cost_usd": "0.0023",
"burst": { "active": false },
"egress": { "result": "pass", "dimension": null, "value": null, "data_class": "internal" }
}
}Generated by Anoman — the guarded LLM gateway. Counts every AI call guarded through Anoman, including our own teams' internal use. For a full security review or vendor questionnaire, contact us for provider documentation.
Generated: Oct 8, 2026
Our Commitments
- Data location: Account data and logs are stored in Jakarta (subprocessors listed on the privacy page). A request leaves Indonesia only when the model you choose is processed elsewhere, and every model lists its processing region.
- 0% markup: Token pricing is pure pass-through at provider cost. Revenue comes from platform subscriptions, not token margin.
- Transparency: Every API response includes an
_anomanmetadata block showing guardrail results, cache status, routing decision, and actual cost. - No AI training on your data: Anoman never trains on your data, and guarded models' providers never train on it either; the may-train community lane is opt-in.
Uptime & SLA
We target 99.9% monthly API gateway uptime. Our batch routing system includes an automatic SLA escalation: if a batch job reaches 80% of its SLA window without completing, it is automatically promoted to real-time routing at no extra charge.
System status and active incidents are published at anoman.io/status.
Data Handling
Our data handling principles:
- API keys are bcrypt-hashed before storage — raw key shown exactly once
- Response cache entries are partitioned per customer — cross-customer cache leakage is treated as a critical security bug
- All database writes stay in the Jakarta region — currently Anoman's only live region
- Sensitive data is detected and masked on every request by our PII detection engine — SG NRIC, Indonesian NIK, Malaysian MyKad, Thai National ID, emails, and credit cards (phone, IP, and URL on request)
Provider Relationships
Anoman routes to leading LLM providers through our routing engine. Every provider relationship is governed by their respective data processing agreement. We select providers based on latency performance, reliability, and regional availability. Provider health is monitored in real time and displayed on the status page.
Security
Security controls sit in the gateway, the data layer and our operations. This section covers our infrastructure security posture, encryption standards, access controls, and how to report vulnerabilities.
Infrastructure Security
All production workloads run in our Indonesia data center (Jakarta). Our infrastructure:
- Private network with no public-facing database endpoints — all services communicate over private IPs only
- Primary database with hot standby — automatic failover, continuous WAL archiving, point-in-time recovery
- In-memory cache with append-only persistence — private network only, hourly snapshots
- Cluster nodes with per-service IAM roles (least-privilege)
- Workload identity — no long-lived secret files in containers
- Daily encrypted backups to Indonesia-resident object storage, 14-day retention
Encryption
- TLS 1.3 required for all external connections
- Database storage encrypted at rest (AES-256)
- API keys hashed with bcrypt before storage — raw key shown once at creation and never stored
- Secrets managed via a private secret store — no .env files in production containers
Access Control
Dashboard access uses a session-based authentication layer with short-lived JWT sessions (1-hour max age). RBAC enforces five roles, checked server-side on every mutating request — not just hidden in the UI:
- Owner — full control: billing, team, every key and policy
- Admin — manage members, API keys, and guardrail policy
- Admin (read-only) — SOC 2-friendly auditor seat: read everything, change nothing
- Member — use the gateway, manage their own keys and policies
- End-user — governed Copilot-only seat: no dashboard, no key minting
The ops dashboard is protected by HTTP Basic Auth in production.
Incident Response
Our incident response process follows a detect → contain → eradicate → recover workflow:
- Automated alerts via our monitoring stack for error rate spikes, SLA breaches, and anomaly detection triggers
- On-call rotation with 15-minute acknowledgement SLA
- Affected customers notified within 72 hours of confirmed breach
- Post-incident reports published on the status page
Vulnerability Disclosure
We operate a responsible disclosure policy. If you discover a security vulnerability, please report it to [email protected] with a description of the issue, steps to reproduce, and potential impact. We acknowledge reports within 48 hours and aim to resolve critical issues within 7 days.
Compliance & Certifications
Frameworks we build against:
- UU PDP (Law No. 27/2022) — Indonesian personal data protection law. UU PDP-ready: account data and logs are stored in Jakarta, and each model's processing region is disclosed.
- GDPR principles — applied globally as a baseline standard
SOC 2 certification is on our roadmap for Enterprise customers. Contact us at [email protected] for our current security questionnaire.
Contact
For trust and security questions, contact PT Anoman Artifisial Informasi at [email protected]. For enterprise security reviews and questionnaires, please use the same contact.