KAISTA CLOUDTrust Center
SECURITY / DATA / POLICIES

A clear account ofwhere data goes.

This page documents the controls and data handling implemented by Kaista Cloud today, plus the policy documents required before public launch.

Secure glass data channels carrying light into a protected compute core
CONTROLLED DATA PATHEvery transfer has a defined boundary.
DATA PATH / VERIFIED
01Your application
02Kaista Cloud
03TongYuan upstream

Kaista Cloud authenticates the key, reserves credits, and proxies fixed upstream endpoints.

LEDGER / STORED

The usage ledger stores

  • Account identifiers
  • API key prefix and irreversible hash
  • Model and token counts
  • Reservation, charge, and refund state
  • Request ID and timestamps
LEDGER / NOT STORED

The usage ledger does not store

  • Raw Kaista Cloud API keys
  • The TongYuan upstream key
  • Prompt or response bodies
  • Payment card data in the browser
API content must still be sent to TongYuan to perform inference. Upstream and cloud-infrastructure logging and retention must be disclosed in the final Privacy Policy.
IMPLEMENTED CONTROLS

Controls implemented today

SERVER-ONLY SECRETS

Upstream and Supabase administrative keys remain in server environments.

HASHED API KEYS

Raw customer keys are shown once; the database stores a SHA-256 hash.

ATOMIC BILLING

Credits are reserved first, settled on success, and released on failure.

ROW ISOLATION

Supabase RLS limits wallets, keys, and usage records to their owner.

FIXED UPSTREAM

The proxy only permits fixed TongYuan HTTPS domains and routes.

REQUEST LIMITS

JSON bodies are capped at 2 MB and upstream calls have a timeout.

LAUNCH DOCUMENTS

Required before accepting payment

These documents need the legal company name, operating jurisdiction, payment provider, and refund decisions before they can be finalized.

DRAFT REQUIRED

Terms of Service

Legal entity, liability cap, suspension, and termination

DRAFT REQUIRED

Privacy Policy

Retention, subprocessors, cross-border data, and contact

DRAFT REQUIRED

Acceptable Use Policy

Prohibited uses, abuse response, and provider restrictions

DRAFT REQUIRED

Credits & Refund Policy

Expiration, eligibility, disputes, and tax handling

DRAFT REQUIRED

SLA & Support Policy

Availability target, maintenance notice, and response times

This is a product and technical transparency summary, not final legal terms. Qualified counsel should review the launch documents before public operation.