Skip to content

Security

Understand processing location, account access and deployment-specific security controls.

Check Where Your Data Is Processed

Local and hosted workflows have different data flows. Review the selected service and its consent notice before sharing content. Read the Privacy Policy for account, demo and provider handling.

Data privacy and processing location

Privacy depends on the workflow you select.

Local and hosted workflows

Local inference can keep inputs on the device when no hosted connection is enabled. Hosted gateways and live website demos send the submitted content to the disclosed services.

Provider disclosure

Before a live demo request, review its consent notice for the gateway, model provider and permitted input. Use public or synthetic data where the demo requires it.

Storage and retention

Account records, usage limits, workspace history and infrastructure logs have different retention rules. Clearing a screen does not retract information already sent to a provider. Read the Privacy Policy and the relevant demo notices.

Network access

Protect the endpoint you actually use.

HTTPS and access

Use HTTPS for hosted endpoints. For a local service, follow the administrator configuration for authentication, network exposure and certificates; this website does not certify a universal device firewall setup.

Remote access

Use only the remote access or MeshStack configuration supported by your release. An online control plane or a running adapter is not proof of an authenticated peer tunnel.

Troubleshooting safely

Approve the supported operating-system elevation prompt when required. Do not disable your firewall or UAC, remove another VPN automatically, or expose an unauthenticated admin service to resolve a connection issue.

Accounts and API keys

Use credentials for the right service.

Website account

Sign in with your own THOX account. Use the password reset flow if needed, and keep account recovery messages private.

Inference keys

Eligible accounts can create and revoke ThoxLLM Cloud keys at Dashboard > API Keys. The secret is shown when created; store it securely and replace it if lost or exposed.

Separate permissions

An inference key, an OAuth application and a registered device grant different capabilities. None is evidence of permission to run device commands.

Deployment controls

Confirm available roles, SSO and multi-factor authentication with the administrator for the specific product. Do not assume these are enabled by a generic support page.

Encryption and device protection

Validate controls for your deployment.

Transport and storage

HTTPS protects the transport connection. Storage encryption, backups and provider retention are separate controls that must be confirmed for the selected service.

Hardware features

Secure boot, TPM or HSM availability depends on the hardware, firmware and configuration. Verify the device documentation and deployment settings before relying on these controls.

Sensitive diagnostics

Remove credentials, session tokens, private prompts and personal data from diagnostics before sharing them with support.

Updates and security reports

Use release-specific instructions.

Check releases

Confirm the product, installed version and intended release channel before updating. Review compatibility and recovery instructions from the component maintainers.

Recovery

Back up important data using the supported process. Do not assume that an update rollback or factory reset preserves models, credentials or user files.

Report an issue

Use the support contact flow for a security concern. Begin with a concise description and affected version; request a suitable channel before sending sensitive evidence.

Deployment requirements

Confirm evidence and contract terms for your use case.

Regulated information

Before using regulated or confidential data, confirm the processing location, access controls and retention for that workflow. The organization deploying THOX.ai remains responsible for its lawful basis, notices, access controls, retention and data-subject request process.

Certifications and assurances

This page does not assert that THOX.ai LLC or a deployment has completed a SOC 2 Type II audit. Request applicable evidence for the product and deployment instead of treating a support article as a certification.

Required agreements

Contract terms, including any BAA, must be confirmed with THOX.ai sales and legal before use. Availability of a device or hosted feature does not establish that the agreements required for your workflow are in place.

Security Resources