Trust, in pieces you can check.
Most trust pages hand you a wall of logos. We do not have those logos yet, and we will not pretend to. Instead, here is every mechanism that guards your data, each written to be verified, and one honest line about the badge we have not earned.
Start here
Capabilities →
Generated from the configuration we are actually running: what each path checks, what it measured, and where a measurement no longer describes the live system.
Your data, plainly →
What we never do, what stands guard right now, and what you control. In plain words.
Where your code goes →
The exact path a request takes, which providers can see it, and the no-training guarantee.
The measured numbers →
Every claim with its population, sample size and date, the paths where we have no oracle, and the claims we have withdrawn. We publish when we are wrong.
Terms of service →
The plain-language agreement. No dark corners.
SOC 2? Not yet. Here is what we do instead.
We are a small company. Claiming a SOC 2 report we do not hold would be the first untrustworthy thing on a trust page. So we do not. What we offer instead is the set of mechanisms an auditor would look for, stated concretely and checkable today:
- No prompt text in your records. Your prompts and responses are never kept in your usage records. History holds token counts, timings, and costs. Not text. When an answer passes verification we cache it together with the question that produced it, so it can be reused; send
tirtha.no_cacheto skip the cache for a request. - Content-hash cache addressing. Cache entries are keyed by a hash computed on our servers, so a crafted URL cannot trick the cache into serving someone else's data. The exact bug class behind the famous cache leaks cannot happen here by construction.
- Not found, not access-denied. Ask for another account's resource and you get "not found." We do not even reveal there is something to deny.
- Server-side spend caps, on by default, so a leaked key cannot quietly become a large bill.
- No training, verified in writing — ours, and every provider that touches your traffic.
When we do pursue a formal report, we will say so here, with the date we started and the date we finished. Not before.
What a trust center will hold (named in order)
Live today
The security and privacy pages above. Per-request metering you can see. Invite-only, opt-in from the first touch. A real person answers [email protected].
Coming, in this order
A named data-retention policy. A subprocessors list (who else can touch a request). One-click data export. One-click deletion. Each one only reduces what we hold or shows you what we already do.
Do not trust us. Check us.
Every claim linked from this page is written to be checkable. Email [email protected] and ask how any of it works. A real person answers, and if we get something wrong we say so in public. In July 2026 we caught our own best benchmark result being false and published the finding the same day. That is the standard we hold ourselves to, so you can imagine how we treat your data.
Pre-beta honesty: Tīrtha is small. We would rather earn trust slowly with mechanisms you can check than quickly with badges we have not earned. · Security · Privacy · Back to overview