Draft DPA Summary
This is a public beta summary of the data processing terms CostLayers expects to support for enterprise review. It is not a signed data processing addendum and does not replace negotiated terms.
Effective draft date: July 9, 2026. Contact: rishabh@costlayers.com.
Review status: every control and service level below is proposed or source-observed, not a current contractual commitment. Production hosted API use should wait for a signed DPA, named subprocessor schedule, deployment evidence, and agreed terms.
Roles
| Context | Expected role |
|---|---|
| Local audit and proof commands | Customer controls local artifacts on customer systems. CostLayers does not receive source code by default. |
| Hosted dashboard and metering | Customer is controller or business. CostLayers acts as processor or service provider for hosted account, keyed dashboard, usage, and proof metadata. |
| Hosted API invoice mode | CostLayers acts as processor or service provider for gateway processing needed to meter and forward customer-authorized provider traffic. Customer remains responsible for its provider account and provider terms. |
| Customer-selected model provider | The provider processes traffic under the customer's provider account and terms. Provider-side retention and deletion are outside CostLayers control. |
Processing Scope
- Provide local audit, proof, quality, cache, dashboard, metering, and hosted API invoice features.
- Measure token counts, model costs, quality labels, cache hits, provider calls avoided, and proof hashes.
- Target account separation, keyed dashboards, abuse prevention, rate limits, support, deletion, and incident response, subject to deployment evidence and negotiated terms.
- Forward hosted API invoice mode requests to the customer-selected model provider when explicitly enabled.
Data Categories
- Account and access data: email address, repo key status, dashboard path, plan label, timestamps, and rate-limit counters.
- Usage and proof metadata: token counts, cost counters, model names, cache labels, quality labels, request hashes, response hashes, and proof hashes.
- Local artifacts: files under
.agentspend/and CostLayers-created local agent integrations controlled by the customer unless the customer shares or syncs hosted metrics. The CLI attempts to ignore.agentspend/in the repo root.gitignoreand reports when manual cleanup is needed. - Hosted API invoice traffic: prompts, request bodies, provider responses, provider authorization, and provider account traffic passing through the gateway for the explicit workflow.
- Support and security data: emails, reports, screenshots, logs, and metadata the customer chooses to provide.
Retention and Deletion
| Item | Beta target |
|---|---|
| Hosted account/access rows and usage metadata | Unverified target: active key lifetime plus no more than 180 days after inactivity. |
| Response-cache opt-in bodies | Source-observed opt-in and 30-day default; deployment, purge-race, and backup evidence missing. |
| Security and abuse logs | Unverified 90-day target; deployed log inventory and job missing. |
| Support/security correspondence | Unverified 24-month target subject to documented exceptions. |
| Deletion requests | Targets: immediate revocation and primary-row deletion for reachable API requests, 2-business-day manual acknowledgement, 30-day validated primary deletion, and 30-day controlled-backup expiry. No operating-history SLA or backup proof is attached. |
Proposed Security Measures
- TLS/HSTS target for public and API endpoints; deployed configuration evidence missing.
- Source-observed keyed paths and CLI URL hiding; complete tenant isolation and non-bearer enterprise authentication remain targets.
- Source-observed rate-limit, abuse, and revocation paths; distributed production evidence missing.
- Source-observed hash-based public artifact formats; raw-data non-persistence requires deployment evidence.
- Source-observed response-cache opt-in and purge paths; concurrency, restart, backup, and operator-access tests missing.
- Source-observed out-of-repo key-storage attempt where supported; platform permissions unverified.
- Security-header target including content type, frame, referrer, cache, HSTS, and CSP; deployed captures missing.
Subprocessors
The current beta subprocessor list is maintained in the public security artifacts at /docs/security-artifacts.html. Enterprise review should finalize a named infrastructure subprocessor schedule before production hosted API use.
Incident and Assistance Targets
- Security contact: rishabh@costlayers.com.
- Unverified target: acknowledge vulnerability reports within 2 business days.
- Unverified target: triage plausible hosted customer-data reports within 1 business day.
- Unverified target: notify affected customers within 72 hours after confirmation where legally and operationally feasible.
- Unverified target: acknowledge data-subject and deletion requests within 2 business days and handle them under negotiated deletion terms.
Current Exclusions
CostLayers does not claim SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or BAA readiness in the beta. Customers that require those controls, private deployment, SSO/SAML, enterprise RBAC, custom retention, audit logs with contractual support SLAs, or named subprocessor commitments should complete enterprise review before production use.