Security and governance
Security and governance built into every call
See it working
What you get
Envelope-encrypted vault
Vendor keys are sealed per workspace, write-only, and injected server-side; they never reach your code or your agents.
Workspace isolation
Forced Postgres row-level security on every tenant table, and per-workspace keys for the cache and stored bodies.
Scoped API keys
Scopes, spend limits, expiry dates, IP allowlists and zero-downtime rotation with a grace period.
Roles
Owner, admin, developer, billing and viewer, mapped to what each can read and change.
Hash-chained audit log
Member, role, key, recovery-code and billing changes, each with who did it. A changed or deleted entry breaks the chain.
Security events
A key used from a new IP raises an alert; sign-ins are rate-limited with account lockout; owners hold one-time recovery codes.
How it works
Add vendor keys; they're sealed in your workspace's vault and never shown again.
Create an API key per app or agent with only the scopes and budget it needs.
Review sessions, roles and the audit log; rotate keys without downtime.
curl https://api.gridrouter.io/v1/keys \
-H "Authorization: Bearer $GRID_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Research agent",
"scopes": ["call", "catalog:read"],
"limit_micro": 5000000,
"limit_reset": "day",
"allowed_ips": ["203.0.113.0/24"]
}'Questions
Can GridRouter staff read my vendor keys?
No. Keys are encrypted under your workspace's key, write-only through the API, and decrypted only inside the worker that makes the call.
Is GridRouter SOC 2 certified?
Not yet. Our controls and the latest audit are published on the security page, and we'll say so when a report exists.
How do I report a vulnerability?
See /.well-known/security.txt and the security page for the disclosure process.
More in GridRouter
- Unified API and routingAsk for a capability, not a provider. GridRouter picks the provider, falls back on a miss or an error, and answers in one schema.
- MCP serverPoint any MCP client at one URL and your agent can search the catalog, get a quote and call any capability, inside the budget you set.
- WaterfallsPut providers in order, choose how fast and how far to go, and publish the result as a versioned endpoint your code and agents can call.
- Logs and log explorerSee exactly what every provider returned, what it cost and how long it took, from the dashboard, the API, the CLI or your agent.
- Vendor billing verificationGridRouter checks what each provider charged against what its own pricing says, call by call, and hands you the mismatches as a CSV.
- Private cacheStop paying twice for the same person or company. Every answer is cached for your workspace only and reused until its fields expire.
- Alerts, webhooks and integrationsHear about a failing provider, a runaway agent or a wrong charge in seconds, in the tools your team already watches.
- Provider catalog and docsFind the right provider for a capability, see how it bills and what its API looks like, before you sign a contract.