No inline content path
Metadata-only
Send provider, model, token, cost, and workload labels after your own provider call. Prompts and responses stay out of Varsten.
Choose the data path that matches the workload, keep credentials bounded, and preserve a direct fallback for production traffic.
01 · Data paths
No inline content path
Send provider, model, token, cost, and workload labels after your own provider call. Prompts and responses stay out of Varsten.
Provider key stays local
The Varsten key authenticates the optimized path. Your provider key remains in the application for direct fallback.
Connected provider credential
Varsten processes content in transit and uses a connected provider credential. This path should be reviewed before sensitive use.
02 · Controls
Project-scoped credentials and organization ownership checks isolate customer resources across the control plane.
Application roles and infrastructure permissions are scoped to the resources required for their runtime responsibilities.
Security-sensitive account, credential, and administrative actions are designed to produce attributable audit records.
Public application and API traffic uses TLS. Sensitive configuration is kept out of client-side code and analytics.
03 · Reliability
SDK wrappers can bypass Varsten for eligible transport or Varsten-origin failures before output starts.
Provider-origin errors, deliberate budget caps, and mid-stream failures are surfaced rather than retried blindly.
Repeated Varsten failures open a local breaker so applications do not pay the same failed timeout on every call.
Current posture
Varsten is building toward formal assurance but does not claim a SOC 2 report, penetration-test certification, or compliance status that does not exist.
For questionnaires, vulnerability reports, architecture review, or available security materials, email security@varsten.ai.