# Trust, security and compliance at Tokenomy.

> Security, privacy and compliance at Tokenomy. BYOK isolation, per-tenant encryption, RLS-enforced multi-tenancy, SOC 2 in progress (Q4 2026), GDPR and DPA available.

Source: https://tokenomy.ai/trust
Last updated: 2026-09-08
Publisher: Tokenomy — FinOps for AI
License: free to quote with attribution and a link to the source URL.

Tokenomy is BYOK-first. Provider keys stay in your accounts. We never proxy training data. Every table in our data plane is row-level-security isolated per tenant.

## Security posture

How we protect your data and your keys.

- BYOK — provider spend and secrets stay on your accounts
- Per-tenant AES-256 encryption at rest, TLS 1.3 in transit
- Row-level security enforced on every multi-tenant table
- Least-privilege service accounts, rotated secrets, audit logs

## Compliance

SOC 2 Type II in progress with completion targeted for Q4 2026. GDPR and DPA available today. HIPAA on request for Enterprise.

## Privacy

We do not train on customer prompts or completions. Usage metadata is retained per your plan (30 days on Starter, 12 months on Pro, custom on Team/Enterprise).

## Related pages

- [Plans and retention](https://tokenomy.ai/pricing)
- [Documentation](https://tokenomy.ai/documentation)
- [Contact security](https://tokenomy.ai/contact)
