Security

How we handle your eval data

Fyntune captures production LLM inputs and outputs for evaluation — which may include user-submitted content, internal documents, and proprietary prompts. We designed our data handling around per-team isolation, 30-day maximum raw data retention, and strict no-training policies. We don't claim certifications we haven't completed. What we describe here is what we've actually built.

Security questions? [email protected]

AES-256 Encryption at rest for all eval data
TLS 1.3 In-transit encryption on all connections
30 days Maximum raw output retention window

Security controls designed for production data

We tell you what we've built and how we've built it. We don't claim certifications we haven't completed. Where we say "designed with X controls," that means the control exists — not that a third-party auditor has verified it.

Data encryption at rest and in transit

All eval data is encrypted at rest using AES-256. All data in transit uses TLS 1.3. API keys are hashed — Fyntune staff cannot read your API key after issuance.

Eval data isolation per team

Each Fyntune team's eval data is logically isolated — no cross-tenant data access is possible by design. Production LLM inputs and outputs captured for evaluation are never accessible to other teams or used in aggregate model training.

30-day maximum raw output retention

Raw LLM inputs and outputs captured during eval runs are retained for a maximum of 30 days, then permanently deleted. Aggregate eval scores and deltas are kept per your plan's retention policy. Enterprise customers can configure custom retention windows.

Access controls and API key management

API keys support scoped permissions (read-only vs read-write) and can be rotated or revoked at any time from the dashboard. Team admins control which users can create API keys. Enterprise tier adds SSO/SAML integration and role-based access control.

Eval data is not used for model training

LLM inputs and outputs processed through Fyntune's eval pipeline are never used to train, fine-tune, or improve any AI model — Fyntune's or any third party's. This is a firm policy, not a configuration option.

Data residency options for Enterprise

Enterprise customers can configure the geographic region where their eval data is stored and processed. Available regions include US and EU. Data residency agreements are available on request for regulated industries.

Have specific security requirements or need a security review before onboarding your team? Email us at [email protected] — we're happy to walk through our architecture and answer specific questions.