Compute Desk
Security & Privacy
This page provides an overview of the privacy and security practices applicable to Compute Desk's services. Some practices are service-specific and may vary depending on the product or service provided.
Last updated 15 September 2026
Compute Infrastructure
Dedicated infrastructure
Reserved deployments run on dedicated, single-tenant hardware. Compute nodes are provisioned for a single client and are intended to remain dedicated to that client for the duration of the applicable order.
Your data stays yours
Clients control the data and workloads they run on their infrastructure. We do not routinely access or use the contents of client workloads except where reasonably necessary to provide, maintain or secure the service, or where required by law, and we do not sell client data. Clients are responsible for, and retain control of, encryption of their data and the credentials used to access their nodes. Access to provisioned nodes is by client-controlled credentials. Inference requests served by Compute Desk through aggregators are subject to the specific commitments in the Inference Serving section below.
Access controls
Access by our staff to systems supporting client deployments is limited to personnel who require it to operate the service and is granted on a least-privilege basis.
Infrastructure supply chain
We procure compute capacity and data center hosting from third-party infrastructure providers under written agreements. Physical hosting, including facility security and hardware maintenance, is carried out by these providers.
Incident response
If we become aware of a security incident affecting a client's deployment, we will notify the affected client in accordance with our contractual commitments and applicable law, with available details of the incident and the steps being taken.
Data return and deletion
At the end of a deployment, client data will be returned or destroyed in accordance with the applicable agreement and the processes of the underlying infrastructure provider where applicable.
Inference Serving
24-hour deletion of request content
Prompts and model outputs are processed on dedicated GPU nodes and held in operational monitoring logs for at most 24 hours, then deleted. They do not enter databases, caches or backups.
No human review, no training
Compute Desk staff do not view prompts or outputs in the course of operating the service; access is limited to engineers investigating a specific fault or security incident and is recorded. We do not use request content to train, fine-tune or evaluate any model, and we do not share it with model developers or any other third party.
No content moderation
We do not inspect request content. Abuse detection operates on request metadata such as volume, rate and error patterns.
Where it runs
Inference runs on GPU capacity in the United States, the European Union, the United Kingdom or India, depending on the model and available capacity.
What we retain
Request metadata only: model, timestamp, token counts, latency, status and the aggregator identifier, retained for 12 months for settlement, abuse detection and capacity planning.
Trading Services (Compute Trader)
Your book is private to you
The contacts, RFQs, listings, negotiation state and execution details you enter into Compute Trader are private to you. We are not a party to your deals, we never trade against you, and we never match you with anyone automatically. We do not sell your data, we do not publish it or expose it to other users, and we do not mine your book to build market intelligence.
Security
We encrypt data in transit and at rest, with additional encryption applied to sensitive contact details such as names, email addresses and phone numbers. Access by our staff is limited and controlled, and we monitor for security threats and abuse.
For more information about how Compute Trader processes personal information, please see the Compute Trader Privacy Policy.
Security program
We continue to develop our security program as the company grows. We do not currently hold formal certifications such as SOC 2 and will update this page as our program evolves.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Contact
Questions about our privacy or security practices:
