Security & Data Handling

How we handle your model, your keys, and your data.

A Private Season runs your model against our sealed worlds. This page states plainly what we access, where it is processed, what we store, and what we will never do — written for a security or procurement reviewer, and for customers anywhere in the world. The binding version of every commitment here lives in the per-engagement contract, the mutual NDA, and, where applicable, a data-processing addendum.

Your model access and API keys

You give us access to your model — typically an API key or an endpoint. That access is used for one thing: running the agreed evaluation. Keys are stored encrypted, used only for your engagement, and deleted when it completes (or on the schedule set in the statement of work). You pay your own inference costs — the model runs on your account's tokens, not ours. For unreleased models, we offer a run-at-customer option: the evaluation executes inside your environment and the model never leaves it; only the attested scores come back.

Where your data is processed (international transfers)

We are a Swedish company (SagaBench AB) and run evaluations on hardened infrastructure in the European Union / EEA by default. For customers outside the EU/EEA, any cross-border transfer of your engagement data is governed by the mechanism named in the data-processing addendum — for EU/EEA and UK data, the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable); for other regions, the equivalent lawful-transfer mechanism. If your policy requires processing to remain in a specific region, the run-at-customer option keeps your model and its data entirely within your own environment.

Security controls

Your engagement data is encrypted in transit (TLS) and at rest. Access is restricted to the minimum personnel running your engagement (least-privilege) on infrastructure segregated from any other product. Credentials are never stored in plaintext and never leave our controlled environment.

What we record — and what we never do with it

To score and to make every number replayable, we record the model's decisions and transcripts within the evaluation runs. Those results are yours. We do not use your model's outputs to train anything of ours, we do not fold your hidden-world results into the public leaderboard unless you choose to publish, and we do not share your results with anyone without your consent.

Confidentiality is mutual

Every engagement runs under a mutual NDA. We protect your model access, keys, prompts, configurations, and results. You protect what you necessarily see of our sealed worlds and methodology. The confidentiality is asymmetric in content but mutual in structure.

Sub-processors

We keep sub-processors minimal — hosting/compute and business email/invoicing. We maintain a current sub-processor list available to customers on request, and we commit, in the contract, to advance notice of any material change so you can object.

Incident notification

If a security incident affects your engagement data, we notify you without undue delay under the contract — what we know, its scope, and what we are doing about it.

The examiner firewall

The function that issues a certificate has no revenue line into, and no reporting line from, any training product. We are structurally unable to be both a customer's training vendor and the examiner that could bend its result. The hidden holdout worlds are never sold, escrowed, or disclosed — at any price, to any customer, under any NDA. This wall is a published standard, not a private assurance.

If you also train (the contamination firewall)

Training and evaluation worlds are permanently disjoint at the family level, with a one-way membrane: a world ever exposed to training can never be used to certify again. You can never train on the worlds we evaluate you on — that is precisely what keeps your certificate meaningful. When training is offered (a later season), it is a separate world pool under a separate licence, with mandatory disclosure.

Retention and deletion

Your API keys are deleted at the end of the engagement. You can request deletion of your engagement data at any time. The replay packages we deliver to you are yours to keep and re-run indefinitely, on your own hardware, without us.

Personal data (GDPR and equivalents)

The simulation contains no personal data — the worlds and their inhabitants are entirely synthetic — and your model processes no personal data in our runs. Our data-protection surface is therefore limited to ordinary business-contact information (who we email and invoice), for which we act as controller under the GDPR and comparable regimes. In the unusual case an engagement would involve personal data, we put a data-processing addendum in place before any such processing.

Regulatory positioning

SagaBench provides an independent measurement and reporting service. Our "certificate" is an evidence report — not a regulatory conformity certification. We are not a notified body, accredited certification body, or conformity-assessment body under the EU AI Act or any other regime, and we do not present ourselves as one. Where a regulation requires formal conformity assessment, our report can inform your process but does not substitute for it.

Export controls and sanctions

Engagements are provided in compliance with applicable export-control and economic-sanctions laws; we may be unable to serve customers or models in restricted jurisdictions.

Governing framework

Each engagement is governed by a written contract that sets the governing law, dispute-resolution venue, and liability limits (a cap and the exclusion of indirect damages), alongside the data terms above. We work with customers globally and can accommodate common contracting preferences. The certificate itself is never a warranty of your model's behaviour.

What we do not claim (stated honestly)

SagaBench is an independent company. We do not currently hold third-party security certifications such as SOC 2 or ISO 27001, and we say so rather than imply otherwise. The binding, negotiated commitments — data handling, liability, deletion, and any data-processing terms — live in the engagement contract, the mutual NDA, and, where applicable, a data-processing addendum. For security questions or to request our current documentation, email info@sagabench.com.