Security

How Line Three is kept secure.

What Line Three keeps, who is in the path of a request, and what it has not earned yet.

Encrypted in transit. For unclassified work. Not an accredited secure communications line.

Effective on the launch date, which will be posted here. Version 1.0 (pre-launch), October 1, 2026.

Four rules the design follows.

  1. Keep no content.

    Line Three discards prompts and answers once the response is delivered. Data that is never stored cannot leak later.

  2. Encrypt every hop.

    Requests travel over TLS 1.2 or later from your client to Line Three, and over TLS from Line Three to Amazon Bedrock.

  3. Scope every key.

    Each key belongs to one account and carries its own cap, so a leaked key has a known, small limit and can be turned off at once.

  4. Say what isn’t done.

    Every certification not held is listed as “Not held”. Anything planned is called planned.

The path of a request.

Every party a request touches, in order.

  1. Your client

    Your editor, agent, script or app, with your key.

  2. Line Three gateway

    Will check the key, its cap and its rate limit, forward the request, and count tokens for the month. Designed to store no content. Will run in Asen Technology’s own AWS account, with no third-party CDN in front of it.

  3. Model provider

    Amazon Bedrock runs the model that answers, in the AWS US West (Oregon) Region (us-west-2), through the Amazon Bedrock Runtime API (bedrock-runtime), using in-region inference.

  4. Back to you

    The answer streams back the same way. Line Three keeps no copy of it.

Line Three’s gateway and its usage records run in Asen Technology’s own AWS account, in the AWS US West (Oregon) Region (us-west-2), the same region where Amazon Bedrock answers your requests. The gateway calls the Amazon Bedrock Runtime API (bedrock-runtime) there, using in-region inference, not cross-region inference profiles, so requests are processed in that one region. Besides AWS, no other company is in Line Three’s request path, apart from DNS and certificate providers, which never see request content.

What is kept, and what isn’t

Kept

  • Account: Your organization’s name and the contact details of its administrators.
  • Billing: Prepaid credit, balances and refunds, monthly caps, monthly charges, payments, purchase orders and invoices.
  • Keys: Each key’s name and a one-way hash of the key. The key itself is shown once and never stored.
  • Usage: For each request: the time, the key, the model, tokens in and out, and the response status.
  • Connection logs: The source IP address and time of each connection, to the API and to this website.
  • Contact-form messages: What you typed into the contact form, the time it arrived and its reference number.

How long each is kept, record by record.

Not kept

By Line Three:

  • Your prompts.
  • The answers.
  • Files or documents you paste into a request.
  • Anything to train a model on.

Amazon Bedrock’s retention follows AWS’s terms, quoted in the data policy.

Read the data policy

Certifications held today: none.

Line Three is a new service. Each row changes only when the certificate, authorization or agreement exists. Line Three does not inherit any provider authorization.

Approved for DoD use
No. Line Three holds no authorization.
No
FedRAMP
No FedRAMP (federal cloud) authorization is held.
Not held
DoD Impact Level
No DoD Impact Level (IL) authorization is held. Line Three is for unclassified, non-CUI work and makes no IL claim.
Not held
ATO
No authority to operate (ATO) has been issued for Line Three.
Not held
CMMC
No Cybersecurity Maturity Model Certification (CMMC) is held.
Not held
SOC 2
No SOC 2 audit report exists.
Not held
GovRAMP (formerly StateRAMP)
No GovRAMP authorization is held. StateRAMP now operates as GovRAMP.
Not held
TX-RAMP
No Texas Risk and Authorization Management Program (TX-RAMP) certification is held.
Not held
HIPAA · BAA
No business associate agreement (BAA) at launch. Do not send protected health information (PHI); send de-identified text only.
Not offered

The model marks, and where they apply

In US West (Oregon) (us-west-2), the commercial U.S. region Line Three uses, AWS lists all three launch models as FedRAMP Class C (formerly Moderate). FedRAMP Class D (formerly High) and the DoD Cloud Computing Security Requirements Guide (CC SRG; AWS’s table calls it “DoD CSP SRG”) Impact Levels 4 and 5 (IL4/IL5) apply only in AWS GovCloud (US), which Line Three does not use at launch.

The marks are the authorizations AWS lists for each model inside AWS, on its own compliance page. They describe the model at AWS, not Line Three. Line Three does not inherit any provider authorization.

AWS table checked on October 1, 2026.

AWS’s table of Amazon Bedrock model marks (another website) · AWS: these models’ IL4/IL5 approval, in AWS GovCloud (US) (another website)

Found a vulnerability? Tell us.

Security problems in Line Three or this website: a person reads every report. This page is listed in security.txt.

Include
What you found, how to reproduce it, and what an attacker could do with it.
Please don’t
Access other people’s data, degrade the service for others, or use social engineering.
We will
Acknowledge your report within 2 business days, tell you what we will do about it, keep you updated until it is fixed, and credit you if you want credit.
Safe harbor
If you act in good faith, follow this page, and give us reasonable time to fix a problem before you disclose it, we will not take legal action against you for your research.

Questions for an assessment?

Tell us what your security review needs.