Compliance & Trust
Last updated: July 23, 2026
Conduix is a governed LLM gateway operated by iVirtualsoft Corp. It sits between your application and eleven upstream model providers, adding encrypted secret storage, per-tenant PII governance, spend and rate governance, data residency, and an append-only audit trail. This page summarizes our security and compliance posture and points to the agreements and controls behind it. When something below says an agreement is available “on request,” email support@conduix.ai.
Certifications & audits
We publish our real status — nothing here is a claim we can't back. Where a credential is not yet in place, it is labeled as such.
A formal SOC 2 audit has not yet begun. Our append-only audit log has been designed to support future SOC 2 evidence collection.
HIPAA support and a Conduix Business Associate Agreement are in development and not yet available. Do not send PHI through Conduix's own routing today. This unlocks once our BAA program, signed upstream-provider agreements, and complete PHI coverage are in place (see HIPAA & PHI below). Our PHI governance is defense-in-depth — not a substitute for your own HIPAA compliance program.
Data Processing Addendum with EU Standard Contractual Clauses available; request-level data residency; org hard-delete for erasure requests.
Agreements: DPA, SCCs, and BAA
These are the contracts that govern how we process your data. We do not yet offer self-service e-signing — request any of them at legal@conduix.ai or sales@conduix.ai and we will send it for signature.
- Data Processing Addendum (DPA) + SCCs — required for processing personal data of EU/UK residents under GDPR. Our DPA incorporates the EU Standard Contractual Clauses for international transfers.
- Business Associate Agreement (BAA) — in development, not yet available. A Conduix BAA will be required for HIPAA-covered workloads before any PHI is sent through Conduix-covered direct provider routing. Bring-your-own-cloud connector traffic is covered by your own cloud BAA (see below), not a Conduix BAA.
Data-handling controls
Every control below is configurable per organization and, where noted, per API key, and every change is written to your audit log. Full mechanics live in the governance docs.
- PII governance — Conduix detects common structured PII (SSNs, credit cards, emails, phone numbers, IPs) and common secrets (API keys, cloud keys, JWTs, private keys) in requests before they reach a provider. You choose redact (destructive), tokenize (reversible — restored in the response so your output stays usable), or off, plus an on-detection policy of allow / warn / require-acknowledgment / block. Best-effort, auditable defense-in-depth.
- Data residency — pin requests to US, EU, or APAC regions.
- Retention & erasure — the audit log records counts and types of detected data, never the values themselves. Hard-deleting an organization wipes its full data graph, supporting GDPR right-to-be-forgotten requests.
- Secret detection — detected credentials trigger a rotation advisory on the response.
HIPAA & PHI workloads
Conduix provides defense-in-depth PHI and PII governance capabilities today — detection, redaction, reversible tokenization, policy enforcement, and fail-closed, PHI-scoped provider routing. Conduix Business Associate Agreements and full HIPAA production support are currently in development. Two distinct BAA regimes will apply to PHI, and they are not interchangeable:
- Conduix-covered routing (in development) — for direct provider routing, PHI-flagged organizations are pinned fail-closed to an approved provider allowlist; residual PII after a transform blocks the request rather than being silently forwarded. This regime will rely on Conduix's BAA with the upstream provider, under a signed BAA between you and Conduix — both in development.
- Your own cloud connector — traffic routed through a connector configured against your own Azure AI Foundry or AWS Bedrock account is covered by your own BAA with Microsoft or AWS.
Conduix's PII governance is a control that reduces provider exposure — it is not a HIPAA compliance program and not a substitute for a BAA. See the governance docs for the exact routing and audit behavior.
GDPR & international transfers
Conduix processes personal data as your processor under the DPA, which incorporates the EU Standard Contractual Clauses. Details of what we collect, how it is used, and your rights are in our Privacy Policy.
Sub-processors
The current list of upstream model providers and infrastructure sub-processors is maintained in the Privacy Policy (“Sub-processors” section) as the single source of truth. A copy is also available on request for procurement review.
Request an agreement or report an issue
- Agreements & procurement — sales@conduix.ai or legal@conduix.ai.
- Security & vulnerability reports — security@conduix.ai. We acknowledge within 24 hours and provide a fix or status update within 7 days.
- General questions — support@conduix.ai.

