Skip to content

Data privacy and security

How Mango Inference handles your data, and the controls available to you.

Data handling

Not yet published

Mango Inference has not published its terms for prompt and completion retention, or for whether request data may be used to train or evaluate models. These docs will not guess at them: a retention or training claim is a commitment, and an unverified one is worse than none.

If your use depends on a specific answer (a data-processing agreement, a zero-retention arrangement, a deletion SLA), ask before you build on the platform. Email support@mangoboost.io and say what you need in writing.

What you can rely on today is the mechanical side, below.

Encryption

  • In transit: TLS 1.3 over HTTP/2. The API is HTTPS-only: a request to http://api.mangoboost.io is redirected to https://, never served in the clear. Any client that reaches the API is on an encrypted connection.
  • At rest: not published. See the warning above.

Access control

  • Every request is authenticated. A missing, malformed, or unknown API key is rejected with HTTP 401 before the request reaches a model.
  • The key is the boundary. GET /v1/models returns only the models that key may call, so a key that has no access to a model cannot call it.
  • No per-key role or permission model is documented, and no scoped or read-only keys. Until key scoping is documented, treat every key as full access to the account's inference, and separate environments by issuing separate keys rather than by scoping one.
  • Keys are shown once at creation and managed in the console.

Request identifiers

Every response carries x-request-id and x-trace-id. They identify a single request, contain none of its content, and are safe to log. Quote them when you report a problem so the team can find the call. See API reference.

Compliance

Mango Inference has not published certifications or compliance attestations (SOC 2, ISO 27001, GDPR posture, or similar). These docs list none, because listing an unverified one would be a false claim. Direct compliance questions to support@mangoboost.io.