Skip to main content
TokenAtlas
Security & Privacy

Security built into TokenAtlas

TokenAtlas is designed with privacy, transparency, and responsible data handling in mind.

Data handling

TokenAtlas models AI cost scenarios from information you provide. It does not observe your systems, ingest provider usage, or run in the background.

We analyze cost scenarios, not your traffic

TokenAtlas prices the workload inputs you enter — model, token volumes, request counts — against a maintained pricing catalog. It works on the numbers you describe, not on live traffic.

Never provide API keys or credentials

TokenAtlas does not need provider API keys, secrets, or credentials. Please do not paste them into any field, including support messages.

No provider account access

TokenAtlas does not connect to OpenAI, Anthropic, Google, or any other provider account, and does not read your provider billing or usage history.

No prompts, no completions

TokenAtlas is not an LLM proxy. Your prompts and model outputs never pass through it, so there is nothing for us to log or store.

Privacy principles

Data minimization

We ask for what the product needs to work: your workload inputs, and account details if you choose to create an account.

Transparency

What we collect and why is described here and in the Privacy Policy in plain language, without claims we cannot back up.

User control

You can use the calculator without an account. If you have one, you can delete saved scenarios and request account deletion.

Responsible handling

We do not sell your data and do not use it to train third-party AI models.

Full details of what we process and why are in the Privacy Policy.

Application security

The controls below are implemented in the product today. We list only what exists.

Email + Google sign-in

Secure authentication with email verification and supported sign-in providers.

Protected application areas

Authenticated areas are protected to ensure users can only access permitted parts of the application.

Database access controls

Row-level security policies help ensure users can only access data they are authorized to view.

Secure payment processing

Payments are handled by an external payment provider. TokenAtlas does not store card payment details.

A note on compliance: TokenAtlas does not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we will not claim ones we do not have. If your procurement team needs a security review, please contact us and we will respond with the information we do have.

Found a security issue?

We welcome responsible disclosure. Please report suspected vulnerabilities through our contact page with a description and steps to reproduce, and give us reasonable time to investigate before sharing details publicly. Please do not include credentials, personal data, or API keys in your report.

Security FAQ

Does TokenAtlas require API keys?

No. TokenAtlas never needs provider API keys, secrets, or credentials — please don't paste them anywhere in the product.

Does TokenAtlas connect to provider accounts?

No. TokenAtlas does not connect to OpenAI, Anthropic, Google, or any other provider account, and does not read your provider billing or usage history.

What data does TokenAtlas use?

Only what the product needs: the workload inputs you enter, plus your account details if you create an account.

Does TokenAtlas store my prompts or model outputs?

No. TokenAtlas is a cost modelling tool, not an LLM proxy. It does not receive, log, or store your prompts or model completions.

Does TokenAtlas hold security certifications?

No. TokenAtlas does not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we do not claim ones we do not have.

Model your AI costs — no keys, no account connections