Skip to main content

Overview

The LLM Gateway is designed for security-conscious teams and teams building with sensitive data. Compliance controls are enforced at the infrastructure layer, not in application code, so your team can ship AI features without building a custom compliance stack.
If you’re building a full application, consider Aptible’s core platform for secure app and database hosting. Security and compliance guardrails are baked in and fully managed, so you can run your entire stack in a HIPAA-compliant environment without configuring it yourself. Learn more about the Aptible platform.

Compliance Controls Summary

HIPAA & BAA Coverage

Aptible’s BAA covers all models and capabilities accessed through the LLM Gateway. A provider BAA from OpenAI or Anthropic covers the provider’s liability, but it doesn’t give you audit logging, access controls, or de-identification. Those are still your responsibility unless you route through a managed layer like Aptible. To get a BAA with Aptible, go to Settings > Agreements.
Unlike Aptible’s core platform (app and database hosting), which requires a dedicated stack for HIPAA workloads, all LLM Keys are covered under an executed BAA. You don’t need a dedicated stack to send PHI through the LLM Gateway.

Audit Logging

Every LLM request and response is automatically logged with no configuration required. Logs include full request and response payloads, token usage, model, cost, and timestamp. Every log is retained by Aptible for 6+ years, with the past 7 days available for self-serve viewing in the Aptible dashboard; anything older can be retrieved by Aptible Support for forensic or debugging purposes. This gives you the visibility needed to answer security questionnaires, support incident investigations, and demonstrate PHI handling during audits. See Audit Logging for details on viewing logs.

Encryption

All data is encrypted in transit (TLS) and at rest. This applies to all LLM requests, responses, and stored logs.

No Training of Models on PHI

LLM providers accessed through the LLM Gateway are contractually prohibited from retaining or using your data, including PHI, for model training. This is enforced at the infrastructure layer, not just by relying on provider policy. LLM Keys are scoped to your organization, and any member of your organization can create a key and view every key’s metadata; revoking a key someone else created requires the Account Owner role. See LLM Keys for the full permissions model. Model access policies let you restrict which models are available across your entire organization, so you can prevent unauthorized use of specific providers or model versions. Changing the policy itself is restricted to Account Owners. See Model Access Policies for details.

Spend Management

An organization-wide monthly spend limit prevents runaway costs from a misconfigured agent or a compromised key. Once the limit is reached, all key usage in your organization is blocked until the next billing period, or until an Account Owner raises it. See Cost Visibility & Control for details.

LLM High Availability

When a model is available from more than one provider, the LLM Gateway automatically fails over to another available provider if the primary one has an outage — no configuration or client changes required. See Supported Models for details.