Trust Center
Governance you can put in front of security review
SpendFriend sits in the path of your AI traffic. Here's exactly what we see, what we store, and the controls you get over all of it.
Data handling principles
Metadata-first metering
By default we log token counts, cost, latency, and model — never prompt or response bodies. Content storage is strictly opt-in per organization, and DLP hooks are available on Enterprise.
Credentials stay in your vault
Employees use per-person virtual keys that map to provider credentials you control. Nobody touches a real Anthropic or OpenAI key, and revocation is instant and per-person.
Every change is audited
Budget edits, policy changes, and routing decisions are appended to an audit log your compliance team can export. Procurement will ask — now you can answer.
Detection without surveillance
The shadow-AI browser extension observes request patterns and domains to flag billable usage. It never captures page content, prompts, or employee browsing history.
Controls & certifications roadmap
SOC 2 Type II is on the Enterprise roadmap. Security questionnaires welcome — send them to [email protected].
Subprocessors
Anthropic / OpenAI / Google / AWS
Model providers — requests proxied per your routing policy
Stripe
Billing and metered invoicing
Render
Application hosting
Questions for our security team?
We'll walk your security and compliance reviewers through the architecture on a demo call.