Legal hub

Trust & Security

Our security practices, the subprocessors and vendors we rely on, and how enterprise customers can execute a DPA.

Last updated: May 1, 2026

Security & Trust

Infrastructure

Data is encrypted in transit (TLS 1.2+). API keys are stored hashed. Tenant workloads are isolated by tenant ID and workspace credentials.

Access control

Role-based UI routes, plan entitlements, and API key read/write scopes limit what each principal can do. Superuser operations are restricted to designated accounts.

Incident response

Report vulnerabilities or incidents to security@masternode.ai. We acknowledge critical reports within 72 hours.

Subprocessors

Third parties that process data on our behalf. This list may be updated with notice.

NamePurposeRegion
MongoDB AtlasPrimary application databaseUS / EU (customer config)
Razorpay Software Pvt. Ltd.Payments and subscriptionsIndia
LLM providers (via LiteLLM)Model inferenceVaries by model
Qdrant / vector storeEmbeddings and RAG retrievalCustomer deployment

Third-Party Vendors

Infrastructure and SaaS vendors we rely on (see Subprocessors for data-processing details).

  • MongoDB — database
  • Razorpay — billing
  • OpenAI / Anthropic / others — LLM inference via LiteLLM
  • Redis — optional task queue
  • Vercel or self-hosted — frontend hosting (deployment-dependent)

Data Processing Agreement (DPA)

Scope

This DPA applies when you act as a data controller and use MasterNode.ai to process personal data on your behalf. Enterprise customers may execute a signed order form referencing this DPA.

Subprocessing

We engage subprocessors listed above. We provide 30 days notice of material changes.

Security & audits

We implement measures described in Security & Trust. Audit rights are available for enterprise plans by mutual agreement.

Request a countersigned DPA

Email dpa@masternode.ai.

Contact