Infer by Flow7 · Trust Center

Infer By Flow7 Trust Center

Trust center

Infer publishes no trust center and holds no named third-party certification. It does publish a complete, versioned legal and data-protection document set, which is the closest thing it has to a trust surface. Recorded so the absence is a checked fact rather than an unchecked one.

Infer by Flow7 maintains a public trust center covering its security and compliance posture.

AI/ML inferenceLLM API gatewayResponses-compatible APICoding-agent toolingDeveloper toolsUsage-based billingPrepaid billingAgent-nativeAgent SkillsModel routing
Trust center:

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-11'
method: searched
source: >-
  Probed https://infer.flow7.org/security (404) and reviewed every legal document linked from
  https://infer.flow7.org/terms on 2026-08-11.
description: >-
  Infer publishes no trust center and holds no named third-party certification. It does publish a
  complete, versioned legal and data-protection document set, which is the closest thing it has to a
  trust surface. Recorded so the absence is a checked fact rather than an unchecked one.
trust_center: null
trust_center_probes:
  - url: https://infer.flow7.org/security
    status: 404
  - url: https://infer.flow7.org/.well-known/security.txt
    status: 404
certifications: []
certification_count: 0
soc2: false
iso27001: false
pci_dss: false
hipaa: false
fedramp: false
notes:
  - HIPAA is explicitly out of scope — the Terms prohibit submitting protected health information.
  - >-
    PCI DSS is out of scope by architecture: Stripe-hosted Checkout with Sold through Link, LLC as
    merchant of record, and the Terms state Infer does not intentionally receive or store full card
    numbers or card security codes.
  - >-
    The product was days old at probe time (all six Route Notes and every legal version date fall in
    August 2026), so the absence of an audit report is expected rather than anomalous.
published_documents:
  - name: Data Processing Addendum
    url: https://infer.flow7.org/dpa
    version: '2026-08-08'
    regimes: [GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and other US state privacy laws]
  - name: Subprocessor Notice
    url: https://infer.flow7.org/subprocessors
    version: '2026-08-08'
    note: Names six subprocessors by legal entity with role, data categories and location.
  - name: Privacy Notice
    url: https://infer.flow7.org/privacy
    note: Section 9 lists security controls in prose.
  - name: Acceptable Use Policy
    url: https://infer.flow7.org/acceptable-use
  - name: Legal Operator Notice
    url: https://infer.flow7.org/legal-operator
  - name: Terms of Service
    url: https://infer.flow7.org/terms
  - name: Refund Policy
    url: https://infer.flow7.org/refunds
    version: '2026-08-08'
data_handling_commitments:
  privacy_modes: [standard, no-training, zero-retention]
  privacy_mode_source: RelayRequestOptions.privacy in openapi/infer-by-flow7-public-api-openapi.yml
  note: >-
    A per-request privacy mode is part of the wire contract, not just a policy page. Route eligibility
    depends on it, and per-tier privacy_modes are published in the unauthenticated catalog. At probe
    time (2026-08-11) all 66 callable tiers listed exactly ["standard"] and the 17 unavailable
    :official tiers listed none — so no-training and zero-retention are contract-supported but not
    currently offered on any published selector.