Trust center

Security Overview

Last updated: July 15, 2026

Till reduces routine distribution of upstream AI provider credentials. It is a proxy control layer, not a zero-knowledge system or a replacement for your provider’s billing and security controls.

Credential design

Usage-control boundary

Activation and conservative token or spend capacity are reserved before a budgeted request is forwarded, then settled to provider-reported actual usage. A token- or spend-budgeted generation request must declare max_tokens, max_completion_tokens, max_output_tokens, or Google generationConfig.maxOutputTokens. Spend-limited requests require a model in Till’s pricing table; unknown-priced models are rejected. Cost remains an operational estimate and may differ from the provider invoice, so retain provider-side budgets and alerts.

Data path

Request and response bodies transit the Till proxy and the provider selected automatically from configured connections using route/model/default signals. Till does not intentionally persist those bodies in its application database. Infrastructure may retain metadata such as IP address, route, timing, status, and errors. See the Privacy Notice.

Customer controls

Assurance status

Till is an early beta and does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider, FedRAMP, or similar certification. No public penetration-test report, bug bounty, uptime warranty, or service-credit program is currently offered. Operational response commitments are published in the beta support SLA.

Report a vulnerability

Follow security.txt and email security@till.ac. Do not include live credentials, personal data, or exploit payloads in an initial report. Confirmed critical issues target acknowledgment within 60 minutes; other material security reports target acknowledgment within four business hours. See the support SLA for scope and limitations.