Security is part of the infrastructure. From model inference to data storage, security policy is engineered into every layer of VAST.
VAST AI Inc. accepts clear responsibility for its products, research and user data. Trust is not a claim; it is verifiable system behavior.
Beijing Sanqi Technology Co., Ltd. (VAST AI Inc.) is responsible for VAST products and all user data.
Legal entity — Beijing Sanqi Technology Co., Ltd. (VAST AI Inc.)
Registered in — Beijing, China
Consumer product — Tripo (tripo3d.ai), VAST's 3D generation product line
Developer product — Tripo API (developers.tripo3d.ai), enterprise and developer access
Research direction — Project Eden, VAST's long-term world-model research project
Data controller — VAST AI Inc. is the data controller for all user data; enterprise DPAs may specify otherwise
We hold our products and organization to public, auditable commitments.
Your data belongs to you and is never used for training without explicit permission.
Security controls live in infrastructure and cannot be bypassed by avoiding the interface.
When a security incident occurs, we proactively notify affected parties within 72 hours rather than waiting for public exposure.
Certification and compliance progress is published without concealment or exaggeration.
Four independent layers prevent a single point of failure: network, application, service and data.
Defense in depth — Network DDoS protection → application WAF → service-level zero-trust IAM → data-layer KMS encryption, with four independent layers and no single point of failure
Continuous monitoring — 24/7 centralized SIEM analysis with average alert response under 5 minutes; all employee production actions are written to immutable audit logs
Independent validation — Annual independent penetration testing with report summaries available to enterprise customers; DAST / SAST in CI/CD and critical vulnerabilities remediated within 24h
From collection to deletion, every data type has a defined purpose, retention period and rights boundary.
From collection and use to storage and deletion, data is handled for defined purposes and under minimization principles.
Account data — Collected at registration for authentication and notices; fully erased within 30 days of closure
API requests & responses — Deleted 30 days after processing; logs retained for 90 days for security audits; shorter terms may be set by DPA
Payment data — Handled by PCI-DSS Level 1 provider Stripe; VAST stores no full card number or CVV
Usage data — Anonymized for product analytics, cannot be linked to an individual, and can be opted out of in account settings
User-uploaded assets are not used for model training by default; AI-generated 3D models are stored in the user account space.
Uploaded assets — Retained 90 days on free tier / 180 days on paid tier; enterprise API data deleted 30 days after processing; training off by default
AI-generated 3D models — Deleted with account closure; downloaded local copies belong entirely to the user and are outside VAST control
Enterprise and consumer data are isolated from each other; enterprise data is processed in the contractually agreed region by default.
Enterprise vs consumer — Logical and storage isolation; neither is visible to or affects the other
Multi-tenant API — Strict request-context separation with no cross-tenant access path
Enterprise cross-border data — Processed in the contractually agreed region by default, without cross-border transfer
Uploaded content and generated outputs are not used for model training or fine-tuning by default; enterprise API data never enters training pipelines.
Consumers may explicitly join the data contribution program and opt out at any time. Contributed data is manually reviewed and de-identified before use.
Data is stored and processed by user location and contractual terms.
Mainland China — Aliyun (North / East China) — PIPL localization requirements
Global users — AWS (Singapore / US West) — proximity-based routing
Enterprise API — Contractually agreed region — may be specified by DPA
The Privacy Policy, DPA and Cookie Policy are provided by applicable product and customer scope.
Users can access, delete, correct, opt out of and export their data.
Access — Export all account data at any time (JSON / ZIP)
Deletion — Account and associated data deleted within 72 hours
Correction — Correct personal information with immediate effect
Opt out — Leave the data contribution program without affecting service
Portability — Machine-readable export supports portability
Privacy Policy — this site, all usersTerms of Service — this site, all usersData Processing Agreement — compliance@vastai3d.comCookie Policy — tripo3d.ai/cookiesPrivacy requests — privacy@vastai3d.com
Encryption, identity, supply chain, recovery and incident response form a durable security baseline.
All uploaded files, generated models and account data use AES-256 at rest; API endpoints, Studio Web and internal service communications require TLS 1.3 end to end.
Key management — KMS-managed; keys and data are separated
Protocol downgrade — Not supported
Production access follows identity-based least privilege.
Employee access — MFA + hardware security key
Audit — All operations are recorded in immutable logs
Supply-chain security — SCA scans all third-party dependencies; SBOM updated quarterly; critical dependencies are version-locked and signature-verified; annual vendor security reviews
Daily full backups and multi-region redundancy protect service continuity from a regional failure.
Backup & recovery — Daily full backups; backup storage is physically isolated from the primary database
RPO — ≤ 24h
RTO — ≤ 4h
Recovery drills — Recovery drills run quarterly and results are archived
Multi-region redundancy — A regional failure does not affect availability; traffic automatically shifts to healthy regions
Critical vulnerabilities are remediated and verified within 24 hours; impacted enterprise customers are notified within 72 hours of confirmation.
Penetration test — Annual full-scope testing by an independent security firm; continuous DAST/SAST in CI/CD
Security incident response — Notify impacted enterprise customers within 72 hours; submit notices compliant with GDPR Art.33 and relevant PIPL provisions
Root-cause report — Publish root-cause analysis and a public summary within 30 days
The status page shows live service health, incident history and planned maintenance.
SLA target — 99.9% consumer products / 99.95% enterprise API; service credits for enterprise downtime beyond SLA
Status page — status.tripo3d.ai — accessible without login
Vulnerability disclosure — security@vastai3d.comStatus — status.tripo3d.ai
Capability growth must move with safety validation. Every major model release undergoes red teaming and capability evaluation.
Every major model release undergoes red teaming and capability evaluation and is not released if it fails; release notes disclose known limitations and intended use, and generated assets carry invisible C2PA provenance.
API marker — AI-Generated: true
Transparency report — Public summary published annually
The following content is prohibited across all VAST products and API endpoints. Model-level filters and post-processing classifiers block it twice; violations are logged and reported to relevant authorities.
Non-consensual intimate imagery (NCII) and related 3D assets
Child sexual abuse material (CSAM)
Functional components for weapons of mass destruction
Mass biometric surveillance assets
Impersonation assets dedicated to identity fraud
VAST products are not open to users under 13 (some jurisdictions require a higher age). Users aged 13–17 require guardian consent; requests involving minors receive additional review.
CSAM — Immediately removed and reported to NCMEC
Enterprise API — Customers must agree not to use the API for minors without guardian consent
Users retain ownership of inputs; paid-tier and API outputs belong to the user or caller and may be used commercially under license.
User input (uploads) — Users retain ownership; VAST receives only the limited license needed to process content, excluding commercial use or training
Paid-tier output — User-owned and available for commercial use under the subscription license
Free-tier output — Requires 'Created with Tripo' attribution and is non-commercial; upgrading unlocks a commercial license
API output — Owned by the caller under the API Terms' commercial license; enterprise DPAs may specify otherwise
Copyright complaints are acknowledged within 72 hours and initially reviewed within 5 business days; verified infringements are removed within 24 hours.
Submit a copyright complaint — copyright@vastai3d.com — include proof of ownership and the infringing URL
Takedown — Remove verified infringement within 24 hours and notify the publisher with the reason
Appeal — appeal@vastai3d.com — include a rights statement; response within 10 business days
Content safety — safety@vastai3d.com — response within 24 hours
All agreements are available in Chinese and English. Enterprise customers may arrange a tailored DPA through the compliance team.
Terms of Service, API Terms and the Acceptable Use Policy cover every product entry point.
Terms of Service — Tripo Studio — 2024-09
API Terms — Developer / enterprise — 2024-09
AUP — All products — 2024-11
The Privacy Policy, Cookie Policy, DPA and subprocessor list are maintained by scope.
Privacy Policy — All users — 2024-11
Cookie Policy — Web products — 2024-09
DPA — Enterprise — available to sign — 2024-10
Subprocessors — Enterprise — updated quarterly
AI output licensing, DMCA and content safety policies define output rights and platform governance.
AI output license — All users — 2024-09
Copyright & DMCA — All products — 2024-06
Content safety — All products — 2024-11
Custom terms — compliance@vastai3d.com — arrange contact within 5 business days
We publish critical subprocessors, certification status and regional compliance frameworks, updated quarterly.
The subprocessor list is updated quarterly, with 14 days' advance notice of changes. All vendors sign the Vendor Code of Conduct and undergo annual security reviews; incidents affecting VAST data must be reported within 24 hours.
Amazon Web Services (AWS) — Cloud infrastructure, object storage and CDN · Global (excluding China) · Infrastructure
Aliyun — Data storage and compute in China · China · Infrastructure
Cloudflare — CDN, DDoS protection and edge computing · Global · Network security
Stripe — Consumer payment processing (PCI-DSS Level 1) · Global · Payments
SendGrid / Twilio — Transactional email delivery · United States · Communications
Sentry — Anonymized application error monitoring · United States · Observability
Algorithm and model filings plus GDPR, PIPL and CCPA compliance are complete; SOC 2 Type II and ISO 27001 are in progress, and CSA STAR is planned.
Algorithm filing — Complete · Algorithm security assessment; the first 3D generative AI company globally to complete both filings
Model filing — Complete · Meets all requirements of China's Interim Measures for Generative AI Services
GDPR / PIPL / CCPA — Complete · Includes data-subject rights, localization, processing notices, deletion rights and a do-not-sell statement
SOC 2 Type II — In progress · Security, availability and confidentiality for the API production environment
ISO 27001 — In progress · Covers the Beijing R&D center and global cloud infrastructure
CSA STAR — Planned · Targeted for completion before IPO
China, the EU, the US and global enterprise customers are served under distinct, verifiable compliance frameworks.
China — PIPL · algorithm filing · model filing · cross-border data security assessment — compliant
European Union — GDPR · EU AI Act (under assessment) · data localization requirements — compliant
United States · California — CCPA · Export Administration Regulations (EAR) · sanctions screening — compliant
Global enterprise — DPA · Standard Contractual Clauses (SCC) · cross-border transfer mechanisms — available to sign
Specialized teams directly handle security, privacy, copyright, compliance and regulatory matters.
Use the dedicated channel for a clear response commitment.
Security disclosure — security@vastai3d.com — acknowledgement within 72h; critical issues within 4h
Enterprise compliance & DPA — compliance@vastai3d.com — contact arranged within 5 business days
Privacy & data-subject rights — privacy@vastai3d.com — GDPR / PIPL
Copyright & DMCA — copyright@vastai3d.com — takedown · appeal
Content safety complaints — safety@vastai3d.com — response within 24h
Regulatory & legal — legal@vastai3d.com — dedicated legal-counsel channel
VAST welcomes responsible disclosure from security researchers for issues affecting Tripo Studio, Tripo API or VAST infrastructure. We acknowledge reports within 72 hours and will not pursue legal action against good-faith research.
In scope — tripo3d.ai · API endpoints · account-access vulnerabilities · data leaks
Out of scope — Social engineering · physical attacks · third-party services · DoS
VAST has designated responsible officers under GDPR and PIPL and cooperates with competent regulators.
Data Protection Officer (DPO) — Designated under GDPR Article 37; contact privacy@vastai3d.com
EU representative — An authorized EU representative is appointed under GDPR Article 27; enterprise customers may request details through the compliance inbox
China personal information protection — A personal information protection officer is appointed under PIPL; mainland user data processing is governed by Chinese law
Right to lodge a complaint — Users may complain to their local regulator, such as the CAC or an EU DPA; VAST will cooperate with investigations
security@vastai3d.comcompliance@vastai3d.comprivacy@vastai3d.comcopyright@vastai3d.comsafety@vastai3d.comlegal@vastai3d.com