Enterprise Security: Zero-Retention and Data Privacy
Enterprise customers require strict data privacy guarantees. TarqaAI implements zero-retention policies and compliance-first architecture.
Security Highlights
Zero Data Retention
By default, TarqaAI:
- Does not store request content
- Does not log response data
- Only tracks metadata for billing and analytics
- Purges all data after processing
End-to-End Encryption
All data is encrypted:
- TLS 1.3 for data in transit
- AES-256 for data at rest
- No plaintext storage at any point
- Encrypted backups and logs
Compliance Roadmap
TarqaAI is actively pursuing compliance certifications and currently aligning with:
- SOC 2 Type II: In progress — security, availability, and confidentiality controls are being audited
<!-- - GDPR: Aligning data practices with European data protection requirements -->
<!-- - DPDP: Built for India's Digital Personal Data Protection Act — founded and headquartered in India -->
- HIPAA: Enterprise plan — data processing agreements available on request
Audit Logging
Track every API call:
- Who made the request
- When it was made
- Which model was used
- Response metadata
- No sensitive data logged
VPC and Self-Hosted Options
For maximum control:
- Deploy within your private cloud
- Keep data within your infrastructure
- Full compliance with data residency requirements
- Enterprise-grade security controls
Best Practices
Use environment-based API keys - Separate dev/prod access
Enable audit logging - Track all usage
Set IP whitelist - Restrict access to known networks
Rotate keys regularly - Automatic 90-day rotation
Monitor access patterns - Alert on unusual activity
Enterprise security isn't optional - it's built into TarqaAI from the ground up.