---
title: "Trust | Recovea"
description: "How provider keys are sealed, why the meter has no field for your content, and what can stop a request."
canonical: "https://recovea.ai/trust/"
source: "https://recovea.ai/trust/"
---

Trust at Recovea

# Your keys are sealed. Your content is never stored.

Mechanisms, not promises.

## Custody

Your provider keys stay yours: sealed, bound to your workspace, never written to a log.

The control plane seals them. The gateway opens them, one request at a time.

## The mechanisms

### Keys

- **Sealed**
  Sealed with authenticated encryption, your workspace identity bound into the cipher itself. Ciphertext from another workspace does not open.
- **Opened**
  Every decryption is a call to a separate key service: access-gated, logged, revocable.
- **Held**
  In memory, on the hot path. Never a log, never a disk.

### Content

- **Not stored**
  The metering schema has no field that can hold a prompt or a reply.
- **Not trained on**
  What was never stored cannot be trained on or resold.

### Access

- **Roles**
  Owner, Admin, Member, Billing, Viewer. Enforced on the server.
- **Analytics**
  Cookieless, no recordings, and never a spend value, key or ledger row.

### Leaving

- **One line out**
  Change the base URL back and we are out of the path.
- **Receipts travel**
  Export the chain and re-derive it without us.

The specific technologies and configuration are not on this page. Ask, and we will walk your security team through them.

In the path

Designed to fail open: if the gateway degrades, traffic goes straight to your provider. The only stop is a cap you armed.

[See the proof](https://recovea.ai/proof/)

- [A cap you armedRefused before your provider is called. The answer is 402.](https://recovea.ai/docs/products/cap/)
- [A key you killedIts requests stop at the door. No dollar limit, every plan.](https://recovea.ai/product/)

## What’s already true

No roadmap on this list.

- Your provider keys stay yours: sealed, bound to your workspace, never written to a log.
- The metering schema has no field that can hold a prompt or a reply.
- Receipts are on by default, on every plan — Free included.
- Admission runs before your provider does.
- Designed to fail open.
- Unlimited seats on every plan.
- We take no money from a party we rate.
- You’ll have a reply within one business day.

## Report a problem

Bug reports, billing problems, and security reports are always answered, on every plan.

[Email us](mailto:contact@recovea.ai)
