Legal
Security
Since 9 October 2026, System1 Models operates under the name Decision Models (decisionmodels.io). References to System1 Models and system1models.ai in this document mean Decision Models and decisionmodels.io; nothing else changes.
Last updated: 9 October 2026
System1 Models is built so that the safest thing is the default: EU processing, no stored request content, minimal logs.
Data handling
- No content retention. States, questions, images and answers are held in memory only for the duration of the request. They are never written to logs, databases or disk and never used for training. See Data retention.
- Metadata only in logs: request ID, key ID, model, tier, token count, latency, status. Never content.
- Processing locations: API gateway and database at Hetzner in Helsinki, Finland; EU inference at UpCloud in Helsinki (data centre FI-HEL2), which hosts our always-on GPU and, at peak load, additional EU-tier servers. EU-tier requests always stay in the EU. Peer-to-Peer first uses spare EU capacity; when busy, Lium GPU providers in various countries may handle requests only for keys with "Allow worldwide processing" enabled. Without opt-in, Peer-to-Peer stays in the EU. Zero payload retention applies on every node.
Encryption
- TLS 1.2+ for every connection to the API, dashboard, MCP server and status page.
- Encrypted and authenticated connections between the gateway and GPU servers (WireGuard tunnel plus a service token).
- Encrypted database backups, stored in the EU (Hetzner, Helsinki).
Keys and access
- API keys are shown once and stored only as salted hashes. You can create, label, restrict to a tier, and revoke keys in the dashboard; revocation takes effect immediately.
- Your prepaid balance caps total spend: once it is exhausted, requests are rejected until you top up.
- Sign-in uses a one-time email link or Google; we never store passwords. The email link is single-use and expires after 15 minutes. A signed-in session lasts up to 90 days and stays valid with use (sliding expiry); each sign-in issues a fresh session ID. You can end every session on all devices and browsers with "Log out everywhere" in the dashboard.
- Production access is limited to named administrators, uses SSH keys or two-factor authentication, and is logged.
Isolation
- Every request is authenticated and scoped to one account. There is no shared state between requests other than the read-only model weights.
- EU-tier requests have priority. Peer-to-Peer requests use spare EU capacity at lower priority; only opted-in keys may use worldwide overflow. Existing customers keep EU-only processing unless they opt in for the individual key.
- Images given as URLs are fetched by a restricted fetcher that blocks private and internal network addresses and enforces size limits.
Infrastructure and supply chain
- Data centres of Hetzner (ISO/IEC 27001), UpCloud (ISO/IEC 27001 per provider; always-on GPU and EU peak capacity, with encrypted disks and no request logs; additional servers are deleted after use).
- Container images pinned by digest; model weights pinned by revision and SHA-256 checksum; inference servers do not download code or weights at runtime and accept connections only from our gateway.
- Dependency and image vulnerability scanning; security review of our code before major releases.
Incidents
- Monitoring with alerts to the on-call administrator; status information at system1models.ai/status once live monitoring is connected.
- If a personal data breach affects your data, we notify you without undue delay and within 48 hours at the latest (DPA section 9.2).
Reporting a vulnerability
Email info@productivity-boost.com with the subject "Security". Please give us reasonable time to fix the issue before disclosing it, do not access or change other customers' data, and do not degrade the service (no load or denial-of-service tests). We will not take legal action against good-faith research that follows these rules. A machine-readable contact is at /.well-known/security.txt.
Documents
Data Processing Agreement with technical and organisational measures · Sub-processors · Privacy Policy