Legal
Security
Last updated: 30 September 2026
System1 Models is built so that the safest thing is the default: EU processing, no stored request content, minimal logs.
Data handling
- No content retention. States, questions, images and answers are held in memory only for the duration of the request. They are never written to logs, databases or disk and never used for training. See Data retention.
- Metadata only in logs: request ID, key ID, model, tier, token count, latency, status. Never content.
- EU-only processing: API gateway and database at Hetzner in Helsinki, Finland; GPU inference at Verda in Finland. At present this applies to both tiers; Global-tier traffic will only leave the EU for API keys whose owners explicitly opt in.
Encryption
- TLS 1.2+ for every connection to the API, dashboard, MCP server and status page.
- Encrypted and authenticated connections between the gateway and GPU servers (WireGuard tunnel plus a service token).
- Encrypted database backups, stored in the EU (Hetzner, Helsinki).
Keys and access
- API keys are shown once and stored only as salted hashes. You can create, label, restrict to a tier, and revoke keys in the dashboard; revocation takes effect immediately.
- Your prepaid balance caps total spend: once it is exhausted, requests are rejected until you top up.
- Sign-in uses Google; we do not store passwords. Sign-in by one-time email link is not offered at present.
- Production access is limited to named administrators, uses SSH keys or two-factor authentication, and is logged.
Isolation
- Every request is authenticated and scoped to one account. There is no shared state between requests other than the read-only model weights.
- EU-tier requests have priority; Global-tier requests share the same EU servers at lower priority and may briefly occupy at most one slot of the contracted base capacity, only while no EU-tier request is waiting.
- Images given as URLs are fetched by a restricted fetcher that blocks private and internal network addresses and enforces size limits.
Infrastructure and supply chain
- Data centres of Hetzner (ISO/IEC 27001) and Verda (ISO/IEC 27001, SOC 2 Type II per provider).
- Container images pinned by digest; model weights pinned by revision and SHA-256 checksum; inference servers do not download code or weights at runtime and accept connections only from our gateway.
- Dependency and image vulnerability scanning; security review of our code before major releases.
Incidents
- Monitoring with alerts to the on-call administrator; status information at system1models.ai/status once live monitoring is connected.
- If a personal data breach affects your data, we notify you without undue delay and within 48 hours at the latest (DPA section 9.2).
Reporting a vulnerability
Email info@productivity-boost.com with the subject "Security". Please give us reasonable time to fix the issue before disclosing it, do not access or change other customers' data, and do not degrade the service (no load or denial-of-service tests). We will not take legal action against good-faith research that follows these rules. A machine-readable contact is at /.well-known/security.txt.
Documents
Data Processing Agreement with technical and organisational measures · Sub-processors · Privacy Policy