Trust

Security is part of the infrastructure. From model inference to data storage, security policy is engineered into every layer of VAST.

Company & Trust

VAST AI Inc. accepts clear responsibility for its products, research and user data. Trust is not a claim; it is verifiable system behavior.

Corporate entity & brands

Beijing Sanqi Technology Co., Ltd. (VAST AI Inc.) is responsible for VAST products and all user data.

Legal entity — Beijing Sanqi Technology Co., Ltd. (VAST AI Inc.)

Registered in — Beijing, China

Consumer product — Tripo (tripo3d.ai), VAST's 3D generation product line

Developer product — Tripo API (developers.tripo3d.ai), enterprise and developer access

Research direction — Project Eden, VAST's long-term world-model research project

Data controller — VAST AI Inc. is the data controller for all user data; enterprise DPAs may specify otherwise

Mission & trust commitments

We hold our products and organization to public, auditable commitments.

Your data belongs to you and is never used for training without explicit permission.

Security controls live in infrastructure and cannot be bypassed by avoiding the interface.

When a security incident occurs, we proactively notify affected parties within 72 hours rather than waiting for public exposure.

Certification and compliance progress is published without concealment or exaggeration.

Security at a glance

Four independent layers prevent a single point of failure: network, application, service and data.

Defense in depth — Network DDoS protection → application WAF → service-level zero-trust IAM → data-layer KMS encryption, with four independent layers and no single point of failure

Continuous monitoring — 24/7 centralized SIEM analysis with average alert response under 5 minutes; all employee production actions are written to immutable audit logs

Independent validation — Annual independent penetration testing with report summaries available to enterprise customers; DAST / SAST in CI/CD and critical vulnerabilities remediated within 24h

Privacy & Data Governance

From collection to deletion, every data type has a defined purpose, retention period and rights boundary.

Data lifecycle

From collection and use to storage and deletion, data is handled for defined purposes and under minimization principles.

Account data — Collected at registration for authentication and notices; fully erased within 30 days of closure

API requests & responses — Deleted 30 days after processing; logs retained for 90 days for security audits; shorter terms may be set by DPA

Payment data — Handled by PCI-DSS Level 1 provider Stripe; VAST stores no full card number or CVV

Usage data — Anonymized for product analytics, cannot be linked to an individual, and can be opted out of in account settings

User content & assets

User-uploaded assets are not used for model training by default; AI-generated 3D models are stored in the user account space.

Uploaded assets — Retained 90 days on free tier / 180 days on paid tier; enterprise API data deleted 30 days after processing; training off by default

AI-generated 3D models — Deleted with account closure; downloaded local copies belong entirely to the user and are outside VAST control

Enterprise & personal data protection

Enterprise and consumer data are isolated from each other; enterprise data is processed in the contractually agreed region by default.

Enterprise vs consumer — Logical and storage isolation; neither is visible to or affects the other

Multi-tenant API — Strict request-context separation with no cross-tenant access path

Enterprise cross-border data — Processed in the contractually agreed region by default, without cross-border transfer

Training use policy

Uploaded content and generated outputs are not used for model training or fine-tuning by default; enterprise API data never enters training pipelines.

Consumers may explicitly join the data contribution program and opt out at any time. Contributed data is manually reviewed and de-identified before use.

Data storage & third-party services

Data is stored and processed by user location and contractual terms.

Mainland China — Aliyun (North / East China) — PIPL localization requirements

Global users — AWS (Singapore / US West) — proximity-based routing

Enterprise API — Contractually agreed region — may be specified by DPA

Privacy policy & related agreements

The Privacy Policy, DPA and Cookie Policy are provided by applicable product and customer scope.

Privacy rights & requests

Users can access, delete, correct, opt out of and export their data.

Access — Export all account data at any time (JSON / ZIP)

Deletion — Account and associated data deleted within 72 hours

Correction — Correct personal information with immediate effect

Opt out — Leave the data contribution program without affecting service

Portability — Machine-readable export supports portability

Privacy Policy — this site, all usersTerms of Service — this site, all usersData Processing Agreement — compliance@vastai3d.comCookie Policy — tripo3d.ai/cookiesPrivacy requests — privacy@vastai3d.com

Security & Infrastructure

Encryption, identity, supply chain, recovery and incident response form a durable security baseline.

Encryption & data protection

All uploaded files, generated models and account data use AES-256 at rest; API endpoints, Studio Web and internal service communications require TLS 1.3 end to end.

Key management — KMS-managed; keys and data are separated

Protocol downgrade — Not supported

Identity & access

Production access follows identity-based least privilege.

Employee access — MFA + hardware security key

Audit — All operations are recorded in immutable logs

Supply-chain security — SCA scans all third-party dependencies; SBOM updated quarterly; critical dependencies are version-locked and signature-verified; annual vendor security reviews

Continuity & disaster recovery

Daily full backups and multi-region redundancy protect service continuity from a regional failure.

Backup & recovery — Daily full backups; backup storage is physically isolated from the primary database

RPO — ≤ 24h

RTO — ≤ 4h

Recovery drills — Recovery drills run quarterly and results are archived

Multi-region redundancy — A regional failure does not affect availability; traffic automatically shifts to healthy regions

Vulnerability & incident management

Critical vulnerabilities are remediated and verified within 24 hours; impacted enterprise customers are notified within 72 hours of confirmation.

Penetration test — Annual full-scope testing by an independent security firm; continuous DAST/SAST in CI/CD

Security incident response — Notify impacted enterprise customers within 72 hours; submit notices compliant with GDPR Art.33 and relevant PIPL provisions

Root-cause report — Publish root-cause analysis and a public summary within 30 days

Service availability

The status page shows live service health, incident history and planned maintenance.

SLA target — 99.9% consumer products / 99.95% enterprise API; service credits for enterprise downtime beyond SLA

Status page — status.tripo3d.ai — accessible without login

Vulnerability disclosure — security@vastai3d.comStatus — status.tripo3d.ai

AI Governance & Content Safety

Capability growth must move with safety validation. Every major model release undergoes red teaming and capability evaluation.

Transparency & accountability

Every major model release undergoes red teaming and capability evaluation and is not released if it fails; release notes disclose known limitations and intended use, and generated assets carry invisible C2PA provenance.

API marker — AI-Generated: true

Transparency report — Public summary published annually

Platform content safety

The following content is prohibited across all VAST products and API endpoints. Model-level filters and post-processing classifiers block it twice; violations are logged and reported to relevant authorities.

Non-consensual intimate imagery (NCII) and related 3D assets

Child sexual abuse material (CSAM)

Functional components for weapons of mass destruction

Mass biometric surveillance assets

Impersonation assets dedicated to identity fraud

Protection of minors

VAST products are not open to users under 13 (some jurisdictions require a higher age). Users aged 13–17 require guardian consent; requests involving minors receive additional review.

CSAM — Immediately removed and reported to NCMEC

Enterprise API — Customers must agree not to use the API for minors without guardian consent

IP, copyright & commercial use

Users retain ownership of inputs; paid-tier and API outputs belong to the user or caller and may be used commercially under license.

User input (uploads) — Users retain ownership; VAST receives only the limited license needed to process content, excluding commercial use or training

Paid-tier output — User-owned and available for commercial use under the subscription license

Free-tier output — Requires 'Created with Tripo' attribution and is non-commercial; upgrading unlocks a commercial license

API output — Owned by the caller under the API Terms' commercial license; enterprise DPAs may specify otherwise

Notice, takedown & appeal

Copyright complaints are acknowledged within 72 hours and initially reviewed within 5 business days; verified infringements are removed within 24 hours.

Submit a copyright complaint — copyright@vastai3d.com — include proof of ownership and the infringing URL

Takedown — Remove verified infringement within 24 hours and notify the publisher with the reason

Appeal — appeal@vastai3d.com — include a rights statement; response within 10 business days

Content safety — safety@vastai3d.com — response within 24 hours

Legal Agreements & Policies

All agreements are available in Chinese and English. Enterprise customers may arrange a tailored DPA through the compliance team.

Core service agreements

Terms of Service, API Terms and the Acceptable Use Policy cover every product entry point.

Terms of Service — Tripo Studio — 2024-09

API Terms — Developer / enterprise — 2024-09

AUP — All products — 2024-11

Privacy & data agreements

The Privacy Policy, Cookie Policy, DPA and subprocessor list are maintained by scope.

Privacy Policy — All users — 2024-11

Cookie Policy — Web products — 2024-09

DPA — Enterprise — available to sign — 2024-10

Subprocessors — Enterprise — updated quarterly

Copyright & content policies

AI output licensing, DMCA and content safety policies define output rights and platform governance.

AI output license — All users — 2024-09

Copyright & DMCA — All products — 2024-06

Content safety — All products — 2024-11

Custom terms — compliance@vastai3d.com — arrange contact within 5 business days

Vendors, Certifications & Compliance

We publish critical subprocessors, certification status and regional compliance frameworks, updated quarterly.

Subprocessor governance

The subprocessor list is updated quarterly, with 14 days' advance notice of changes. All vendors sign the Vendor Code of Conduct and undergo annual security reviews; incidents affecting VAST data must be reported within 24 hours.

Amazon Web Services (AWS) — Cloud infrastructure, object storage and CDN · Global (excluding China) · Infrastructure

Aliyun — Data storage and compute in China · China · Infrastructure

Cloudflare — CDN, DDoS protection and edge computing · Global · Network security

Stripe — Consumer payment processing (PCI-DSS Level 1) · Global · Payments

SendGrid / Twilio — Transactional email delivery · United States · Communications

Sentry — Anonymized application error monitoring · United States · Observability

Security & privacy certifications

Algorithm and model filings plus GDPR, PIPL and CCPA compliance are complete; SOC 2 Type II and ISO 27001 are in progress, and CSA STAR is planned.

Algorithm filing — Complete · Algorithm security assessment; the first 3D generative AI company globally to complete both filings

Model filing — Complete · Meets all requirements of China's Interim Measures for Generative AI Services

GDPR / PIPL / CCPA — Complete · Includes data-subject rights, localization, processing notices, deletion rights and a do-not-sell statement

SOC 2 Type II — In progress · Security, availability and confidentiality for the API production environment

ISO 27001 — In progress · Covers the Beijing R&D center and global cloud infrastructure

CSA STAR — Planned · Targeted for completion before IPO

Trade & regional compliance

China, the EU, the US and global enterprise customers are served under distinct, verifiable compliance frameworks.

China — PIPL · algorithm filing · model filing · cross-border data security assessment — compliant

European Union — GDPR · EU AI Act (under assessment) · data localization requirements — compliant

United States · California — CCPA · Export Administration Regulations (EAR) · sanctions screening — compliant

Global enterprise — DPA · Standard Contractual Clauses (SCC) · cross-border transfer mechanisms — available to sign

Legal, Privacy & Security Contacts

Specialized teams directly handle security, privacy, copyright, compliance and regulatory matters.

Specialist contacts

Use the dedicated channel for a clear response commitment.

Security disclosure — security@vastai3d.com — acknowledgement within 72h; critical issues within 4h

Enterprise compliance & DPA — compliance@vastai3d.com — contact arranged within 5 business days

Privacy & data-subject rights — privacy@vastai3d.com — GDPR / PIPL

Copyright & DMCA — copyright@vastai3d.com — takedown · appeal

Content safety complaints — safety@vastai3d.com — response within 24h

Regulatory & legal — legal@vastai3d.com — dedicated legal-counsel channel

Responsible disclosure

VAST welcomes responsible disclosure from security researchers for issues affecting Tripo Studio, Tripo API or VAST infrastructure. We acknowledge reports within 72 hours and will not pursue legal action against good-faith research.

In scope — tripo3d.ai · API endpoints · account-access vulnerabilities · data leaks

Out of scope — Social engineering · physical attacks · third-party services · DoS

Regulatory statements

VAST has designated responsible officers under GDPR and PIPL and cooperates with competent regulators.

Data Protection Officer (DPO) — Designated under GDPR Article 37; contact privacy@vastai3d.com

EU representative — An authorized EU representative is appointed under GDPR Article 27; enterprise customers may request details through the compliance inbox

China personal information protection — A personal information protection officer is appointed under PIPL; mainland user data processing is governed by Chinese law

Right to lodge a complaint — Users may complain to their local regulator, such as the CAC or an EU DPA; VAST will cooperate with investigations

security@vastai3d.comcompliance@vastai3d.comprivacy@vastai3d.comcopyright@vastai3d.comsafety@vastai3d.comlegal@vastai3d.com