Warcai logo
Security record · Warcai

Your prompts stay under your control.

This page names what Warcai protects, which companies process data, and who holds each certification.

No data sales
No Warcai model training
Account-scoped storage

What Warcai protects

Each protection names the party responsible for it.

01

No Warcai model training

Responsible: Warcai policy

Warcai does not use your prompts, outputs or Context Vault entries to train models.

02

Encrypted connections

Responsible: Warcai + providers

Requests between your browser, Warcai and its providers travel over encrypted HTTPS connections.

03

Account-scoped records

Responsible: Warcai controls

Access rules separate saved history and Context Vault records by account.

04

Payments stay with Dodo

Responsible: Dodo Payments

Dodo Payments handles checkout and card details. Card numbers do not pass through Warcai servers.

Encrypted from browser to model

Prompt requests move over HTTPS through Cloudflare and onward to Groq. Saved records use encrypted storage with account-scoped access controls.

Responsible: Warcai + Cloudflare + managed database + Groq

A protected data capsule linking a browser, edge network, storage and model provider

How a prompt moves

A plain-language route from your device to the model and back.

  1. 01

    Your browser

    Your request travels over an encrypted HTTPS connection.

  2. 02

    Edge network

    Cloudflare screens requests before they reach Warcai.

  3. 03

    Sign-in

    Google verifies your identity. Warcai does not receive your Google password.

  4. 04

    Account storage

    Saved history and Context Vault records use encrypted storage and account-scoped access controls.

  5. 05

    Prompt model

    Groq processes the model request. Warcai does not use your prompts or context to train models.

Separate secure data chambers with one account illuminated in amber

Your records stay inside your account

Access rules separate saved history and Context Vault records by account. Other signed-in users cannot read your records through the application.

Responsible: Warcai controls + managed database

Who handles what

Certification labels describe the provider named on the same row.

01

Provider

Google Cloud

Purpose

Sign-in and account services

Provider assurance

SOC 2 Type II · ISO 27001

02

Provider

Cloudflare

Purpose

Hosting and edge network

Provider assurance

SOC 2 Type II · ISO 27001

03

Provider

Managed database

Purpose

History, context and subscriptions

Provider assurance

Encrypted storage

04

Provider

Groq

Purpose

Prompt model processing

Provider assurance

SOC 2 Type II

05

Provider

Dodo Payments

Purpose

Checkout and billing

Provider assurance

PCI-DSS

Assurance follows the provider

Google Cloud, Cloudflare and Groq hold the listed infrastructure assurances. Dodo Payments holds the payment assurance. Warcai does not present those certifications as its own.

Responsible: Each provider named in the register

Three connected assurance medallions representing infrastructure, data and network controls

Your data choices

Warcai offers these controls to every account, regardless of location.

A

Access

Request a copy of the information connected to your account.

B

Deletion

Request deletion of your account, saved history and context.

C

Correction

Ask us to correct inaccurate account information.

D

No selling

Warcai does not sell or rent personal data or prompts.

Report a security issue or request your data

Email security@warcai.xyz with the account email and your request. Do not include passwords, access tokens or full payment details.