Public posture for payments, data protection, and availability — plus a catalog of private compliance documents available after you register an access request.
Relixr is a prepaid AI inference interface. Card payments are handled by a PCI DSS Level 1 merchant of record — Relixr never stores card numbers. Local payment rails use licensed partners under the same principle.
Traffic is encrypted in transit. Account records and credentials are protected with industry-standard controls; API keys are stored hashed. You control whether prompts and completions are logged and how long they are retained. Relixr does not train models on customer data.
Configure logging in Data & Privacy settings. Live uptime is at /status.
Public documents are open. Private documents require a completed access request form — we verify the requester, then share materials for your security review.
What we collect and how we use it
Contract for using Relixr
Cookies and similar technologies
Self-serve processor terms and download
Scope, safe harbor, and how to report
Uptime and incident history
How providers are selected, latency measured, and failures handled — including known biases
26 documents. Click any item to pre-select it on the access form, or request several at once.
Current vendors that process personal data on Relixr’s behalf
High-level diagram of how customer content and metadata move through Relixr
How long categories of data are kept and how deletion requests are fulfilled
How we detect, escalate, and notify customers of personal-data incidents
Plain-language summary of Relixr’s security controls and responsibilities
Workforce and customer authentication, MFA, and privileged access practices
Encryption in transit/at rest and how API credentials are protected
How we intake, triage, and remediate security findings
How code changes are reviewed, tested, and released
Latest third-party test summary when available (under NDA)
Hosting, isolation, and operational controls without internal stack detail
Perimeter controls, DDoS posture, and traffic protection practices
What we log for security and reliability, and how alerts are handled
How production changes are approved, deployed, and rolled back
Roles, severity levels, and customer communication expectations
Continuity objectives and recovery practices for critical services
How Relixr evaluates and contracts with critical suppliers
Completed answers for common vendor security questionnaires
Map of Relixr controls to common frameworks used in enterprise reviews
Workforce security training expectations and cadence
How staff may use systems that can access customer data
How Relixr classifies and handles information by sensitivity
Certificate of insurance when available for enterprise reviews
Independent assurance report when published (under NDA)
These are explicit restraints, not marketing claims. Each one is verifiable — we link to where you can check.
We do not train models on your data
Your prompts and completions are never used to train, fine-tune, or evaluate any model — ours or a provider's. This applies regardless of your logging settings.
We do not store your API keys in plain text
Inference keys are stored hashed. We cannot read them back — if you lose a key, you create a new one. Key prefixes (the first characters) are stored in plaintext for identification only.
We do not silently substitute a different model
The model you request is the model served. The X-Relixr-Model response header reflects the model that ran. If a model is unavailable, the request fails — it is not quietly routed to a different one.
We do not log prompts by default
Request and response content is not stored unless you opt in under Data & Privacy settings. Metadata (tokens, cost, latency, model) is always recorded for billing. — Configure in Data & Privacy.
We do not sell or share usage data
Aggregate or individual usage data is not sold to third parties, shared with providers beyond what is necessary to route your request, or used for advertising.
We do not add hidden markup to inference costs
The X-Relixr-Estimated-Cost header on every response reflects the provider's list price at the time of the request. Relixr's revenue comes from the spread between credit purchase price and provider cost — that spread is our published pricing, not a per-request hidden fee. — Routing methodology.
Direct local-rail purchases may include a tax invoice under Invoices in your dashboard. Card purchases are receipted by our merchant of record.
Security or compliance questions: security@relixr.com.