The usage ledger stores
- Account identifiers
- API key prefix and irreversible hash
- Model and token counts
- Reservation, charge, and refund state
- Request ID and timestamps
This page documents the controls and data handling implemented by Kaista Cloud today, plus the policy documents required before public launch.

Kaista Cloud authenticates the key, reserves credits, and proxies fixed upstream endpoints.
Upstream and Supabase administrative keys remain in server environments.
Raw customer keys are shown once; the database stores a SHA-256 hash.
Credits are reserved first, settled on success, and released on failure.
Supabase RLS limits wallets, keys, and usage records to their owner.
The proxy only permits fixed TongYuan HTTPS domains and routes.
JSON bodies are capped at 2 MB and upstream calls have a timeout.
These documents need the legal company name, operating jurisdiction, payment provider, and refund decisions before they can be finalized.
Legal entity, liability cap, suspension, and termination
Retention, subprocessors, cross-border data, and contact
Prohibited uses, abuse response, and provider restrictions
Expiration, eligibility, disputes, and tax handling
Availability target, maintenance notice, and response times