Skip to main content

Compliance and SOC 2 Type II

LiteLLM is SOC 2 Type II audited. Use this page to collect the documents and answers for your security review.

Get the SOC 2 Type II report​

Request the current report through the LiteLLM Trust Center.

Your data stays in your environment​

You host the LiteLLM gateway in your environment. When you self-host, LiteLLM does not store data or telemetry on LiteLLM servers. The data that the gateway processes stays in your infrastructure. Refer to Data privacy and security.

Some Enterprise functions connect to LiteLLM. Billable request metering sends only a count of successful requests to the LiteLLM collector. Prompts, responses, virtual keys, and your license key do not leave the deployment. The license check uses the LiteLLM license server, or it does the check offline against a signed payload. Refer to Licensing across regions.

Verify the images that you run​

LiteLLM signs each Docker image on GHCR with cosign, from v1.83.0. You can verify the signature before you deploy an image, and you can enforce the check in your CI/CD pipeline. Refer to Verify image signatures.

Vulnerability management​

LiteLLM runs grype scans on all the Docker images that it builds. To report a vulnerability, use GitHub Security Advisories. The full policy is in security.md in the LiteLLM repository.

For large or major security updates, LiteLLM sends an email to Enterprise customers 7 days before public disclosure. Refer to Security best practices. The response time for security patches is in Support and SLA.

Answers for your security questionnaire​

These pages give the answers that security teams ask for most:

For a question that these pages do not answer, book a demo or ask in your Enterprise support channel.

LiteLLM Enterprise
SSO/SAML, audit logs, spend tracking, multi-team management, and guardrails, built for production.
Learn more →