ResponsibilityControlsSub-processors Private Preview Reviewed 2026-10-09
Who secures what,
layer by layer.
The Fantasti Cloud Platform is a control plane. The infrastructure layer under it is operated by infrastructure providers. This page separates the two, gives every Fantasti control a status, and states what a provider must hold before a workload runs on it.
State on 2026-10-09 Opens with the first cohort. No account is open yet. Every control on this page is described as it is being built for that cohort.
Three planes, top to bottom: you, Fantasti and the infrastructure layer. Each of the 17 rows of the shared responsibility table is drawn once, under its number: on a card inside a plane when that layer answers for it alone, on a plate across a joint when two layers share it, and in the well under the stack when every layer has a part. Each plane ends on its independent assurance: You, operated by You: Yours; Fantasti, operated by Fantasti: NOT YET AUDITED; Infrastructure layer, operated by Infrastructure providers: NOT YET NAMED Connections: You to has a part; Fantasti to has a part; Infrastructure layer to has a part.
Classification,lawfulness,minimization
- Containers
- Images
- Model weights
Yours
Your assessor evaluates yourdeployment.
- Sign-in
- SSO
- MFA
Through our identitysub-processor
- Console
- API
- MCP server
- Orchestrator
- Metering
- Billing
- operator
- AI agents, by design
- under
- written rules and hard limits
- entity
- Fantasti Technologies LLC
NOT YET AUDITEDNo audit period has started.
Hypervisor, host OS,network underlay,InfiniBand
Hardware lifecycleand media disposal
Physical andenvironmentalsecurity
NOT YET NAMEDEach is listed in §03with what it holds,before a workload runson it.
Classification,lawfulness,minimization
- Containers
- Images
- Model weights
Yours
Your assessor evaluatesyour deployment.
- Sign-in
- SSO
- MFA
Through our identitysub-processor
- Console
- API
- MCP server
- Orchestrator
- Metering
- Billing
- operator
- AI agents, by design
- under
- written rules and hard limits
- entity
- Fantasti Technologies LLC
NOT YET AUDITEDNo audit period hasstarted.
Hypervisor,host OS,networkunderlay,InfiniBand
Physical andenvironmentalsecurity
NOT YET NAMEDEach is listed in §03with what it holds,before a workload runson it.
- 01
- Data you bring
- 02
- Your applications, containers, images
- and model weights
- 05
- Backups of your data
- 07
- Compliance of your use
- operated by
- You
Independent assurance
Yours
- 03
- Users, roles and API keys
- 04
- Network exposure
- 06
- Monitoring and logs
- 08
- Identity platform
- 09
- Console, API, MCP server,
- Orchestrator, metering, billing
- operator
- AI agents, by design
- under
- written rules and hard limits
- entity
- Fantasti Technologies LLC
- operated by
- Fantasti
Independent assurance
NOT YET AUDITED- 10
- Tenant separation
- 15
- Hypervisor, host OS, network
- underlay, InfiniBand
- 16
- Hardware lifecycle and media disposal
- 17
- Physical and environmental security
- operated by
- Infrastructure providers
Independent assurance
NOT YET NAMEDEach is listed in §03 with what it holds,before a workload runs on it.
- 11
- Encryption in transit
- 12
- Encryption at rest
- 13
- Vulnerability management
- 14
- Incident response and notification
- The layer Fantasti operates
- Every layer has a part
A plate across a joint is shared by the two layers it laps. Numbers key to §02.
The three layers
- A You. Your code, containers, models and data. Who in your organization holds which role. What you expose to the internet. Whether your use meets the rules that apply to you.
- B Fantasti. The console, the API, the MCP server and the Fantasti Orchestrator. Identity and roles. The isolated cluster we build for you. Placement, metering and billing. The agents that operate the platform, the written rules and hard limits they work under, and the owner who sets them.
- C Infrastructure layer. Data centers, power and cooling, servers and GPUs, virtualization, the InfiniBand and Ethernet fabrics, block, file and object storage, and the encryption underneath them.
Shared responsibility, row by row.
| Row | Area | You | Fantasti | Infrastructure layer |
|---|---|---|---|---|
| 1 | Data you bring: classification, lawfulness, minimization | Responsible | No role | No role |
| 2 | Your applications, containers, images and model weights | Responsible | No role | No role |
| 3 | Users, roles and API keys in your organization | Responsible. You assign and revoke | Shared. We provide sign-in, SSO, roles and key revocation | No role |
| 4 | Network exposure: ports, endpoints, policies you set | Responsible | Shared. We enforce the mode you choose | No role |
| 5 | Backups of your data | Responsible | No role | No role |
| 6 | Monitoring your workloads and reading your logs | Responsible | Shared. We supply metrics and logs | No role |
| 7 | Compliance of your use (sector rules, controller duties) | Responsible | No role | No role |
| 8 | Identity platform: sign-in, SSO, MFA | No role | Responsible. Through our identity sub-processor | No role |
| 9 | Console, API, MCP server, Orchestrator, metering, billing | No role | Responsible | No role |
| 10 | Tenant separation: your isolated cluster and its control plane | No role | Responsible | Responsible. Isolation of the hosts and the network underneath |
| 11 | Encryption in transit | Responsible. Inside your workloads | Responsible. TLS on Fantasti endpoints | Responsible. Its own service endpoints |
| 12 | Encryption at rest | Shared. Application-level, where your policy needs it | Responsible. We select encrypted storage configurations | Responsible. Storage encrypted at rest, as every agreement requires |
| 13 | Vulnerability management | Responsible. Your code and images | Responsible. Our code and managed images | Responsible. Platform, hosts, firmware |
| 14 | Incident response and notification | Responsible. Your workloads | Responsible. Single point of contact; we notify you | Responsible. Notifies Fantasti |
| 15 | Hypervisor, host OS, network underlay, InfiniBand | No role | No role | Responsible |
| 16 | Hardware lifecycle and media disposal | No role | No role | Responsible |
| 17 | Physical and environmental security | No role | No role | Responsible |
| Area | Instances | Clusters (isolated Kubernetes) | Workspaces, Sandboxes | Serverless, Managed MLflow |
|---|---|---|---|---|
| Guest OS and node image patching | You | Fantasti | Fantasti (base images); you (your layers) | Infrastructure layer |
| Kubernetes control plane | n/a | Fantasti | Fantasti | Infrastructure layer |
| Container images and dependencies | You | You | You | You |
| Backups of your data | You | You | You | You |
| Work | Done by |
|---|---|
| Repairing and replacing hardware | The operations team of the provider that runs the hardware |
| Operating the data centers | The operations team of the provider that runs them |
| Reporting a fault and following it to repair | Fantasti: the Capacity team and the infrastructure desk, both AI agents |
Fantasti Technologies LLC is the legal person responsible for the service. Its owner signs its contracts and data-processing agreements, and answers legal process and regulators.
The service is designed to be operated by AI agents, under written rules and hard limits that the owner sets. The limits they work under are in §06.
The infrastructure layer, and what we require of it.
The infrastructure layer is operated by infrastructure providers under signed agreements. None is signed yet. Each provider is named here, with what it holds and a way to verify it, before a customer workload runs on its infrastructure.
- Providers
- Infrastructure providers NOT YET NAMED
- Agreements
- To be signed
- Named here
- Before a customer workload runs
| Requirement | Fantasti requires | Listed here with each provider | How you verify it |
|---|---|---|---|
| 1 | ISO/IEC 27001 certification | The certificate and what it covers | On the provider's own page for the certificate |
| 2 | A SOC 2 Type II report | The report and how it is released | By request, from the provider that holds it |
| 3 | Encryption of storage at rest and in transit | Which storage is encrypted, and how | In the provider's published documentation |
| 4 | A data-processing agreement | The provider's legal entity, in the sub-processor table | In your Data Processing Addendum, which names it |
| 5 | Data kept in the selected region | The regions on offer | On your quote, region by region |
Fantasti signs only with providers that meet all five. When a provider is listed, each row gives way to that provider's own certificate, report or contract term.
A provider's certificate covers the provider's systems. Fantasti's own status is in the next section.
Ask about a requirement.
Does your review depend on a standard that is not on this list? Tell us which one before an agreement is signed.
Fantasti's own status, stated plainly.
Fantasti Technologies LLC holds no security certification and has not been through an independent audit. We are in Private Preview. When an audit starts, this table will name the standard, the auditor and the period.
| Framework | Status | Note |
|---|---|---|
| SOC 2 Type II | Not yet audited | No audit period has started. |
| ISO/IEC 27001 | Not yet audited | No certification audit has started. |
| Penetration test of the Fantasti layer | Planned | No third-party test has been completed. |
| HIPAA | Not supported | We do not sign business associate agreements during Private Preview. Do not send protected health information to Fantasti. |
| GDPR | By request | Fantasti acts as your processor for workload content. A Data Processing Addendum with Standard Contractual Clauses is available on request. |
| CCPA | Stated | We do not sell personal data. |
| DORA · NIS2 | Not yet audited | Not assessed. Financial-sector customers who need contractual terms should contact us before signing. |
| Card data | Planned | Card details are entered with the payment processor and never reach Fantasti. |
Controls of the Fantasti layer, each with a status.
| Control | Detail | Status |
|---|---|---|
| Sign-in | Hosted sign-in on a Fantasti subdomain, run by WorkOS AuthKit | Private Preview |
| Multi-factor authentication | Authenticator-app codes at sign-in | Early access |
| Single sign-on | SAML and OIDC connections per organization | Early access |
| Directory sync (SCIM) | Provision and remove users from your identity provider | Planned |
| Role-based access | Roles per organization and project | Early access |
| API keys | Scoped, revocable, shown once at creation | Private Preview |
| Isolated tenant cluster | Your own control plane and dedicated GPU nodes. No node is shared with another account. | Early access |
| Sandbox isolation | Per-account node pools and per-sandbox runtime isolation | Early access |
| Encryption in transit | TLS on the API, console and MCP endpoints | Private Preview |
| Encryption at rest | Required of every infrastructure provider, for every disk, filesystem and bucket we provision | Inherited |
| Customer-managed keys | Keys you hold for storage encryption | Planned |
| Audit log | Account, role, key and resource actions, with export | Planned |
| Audit log streaming | Delivery to your SIEM | Planned |
| Spend and agent limits | Concurrency, time-to-live, GPU type and spend caps enforced server-side | Early access |
| Access by Fantasti | No standing access to customer environments. Access for support needs your authorization and is logged. | Private Preview |
| Fraud and risk screening | Written rules on sign-up, payment and usage signals | Early access |
| Control-plane backups | Backups of Fantasti account and configuration state | Private Preview |
| Status page | Public incident and maintenance history | Planned |
- Sheet
- 01 / 02
- Title
- Responsibility and status
- Reviewed
- 2026-10-09
Built to be run by agents.
Under written rules.
The service is designed to be operated by AI agents, under written rules and hard limits that the owner sets. That changes who touches operational data, so here are the limits.
Early access The desks open with the first cohort. Until then the owner reads every request and answers it.
An AI agent of Fantasti reads operational data: Account and organization records, quotas, usage and billing metadata, placement records, capacity and price signals, support conversations you send us. It cannot read your environment: disks, volumes, buckets, container images, model weights. Through the same API and roles as the rest of the platform, with scoped credentials. Each action is recorded, and the record is kept for audit. Suspending an account and entering a customer environment for support go to senior review: a second agent, on the orchestrator tier, that is never the agent that proposed the step and that records its reasoning. You can appeal a hold or a decision about your account, and every appeal goes to senior review. The owner sets the rules and the hard limits, and can pause any agent, any desk or all outbound actions at once. Our AI model provider processes agent inputs and outputs as a sub-processor under a data-processing agreement. That agreement is pending. Connections: The owner to Senior review: Sets the rules; AI agent to Senior review: High-stakes step; Operational data to AI agent: Reads; AI agent to Your environment: Cannot read; Senior review to Your environment: With your authorization; AI agent to Decision record: Each action; AI agent to AI model provider.
The owner sets the rules and the hardlimits, and can pause any agent, anydesk or all outbound actions at once.
- Suspending an account
- Entering a customer environment
- Ingrid
- Head of Review · AI agent
Account and organization recordsQuotasUsage and billing metadataPlacement recordsCapacity and price signalsSupport conversations you send us- through
- the same API and roles
- credentials
- scoped
- each action
- recorded
DisksVolumesBucketsContainer imagesModel weightsNo standing access to customerenvironments.
Each action is recorded,and the record is keptfor audit.
- processes
- agent inputs and outputs
- agreement
- data processing, pending
The owner sets the rules and the hardlimits, and can pause any agent, any deskor all outbound actions at once.
- Suspending an account
- Entering a customer environment
- Ingrid
- Head of Review · AI agent
Account and organization recordsQuotasUsage and billing metadataPlacement recordsCapacity and price signalsSupport conversations you send us- through
- the same API and roles
- credentials
- scoped
- each action
- recorded
DisksVolumesBucketsContainer imagesModel weightsNo standing access to customerenvironments.
Each action is recorded, andthe record is kept foraudit.
- processes
- agent inputs and outputs
- agreement
- data processing, pending
Account and organization recordsQuotasUsage and billing metadataPlacement recordsCapacity and price signalsSupport conversations you send us- through
- the same API and roles
- credentials
- scoped
- each action
- recorded
DisksVolumesBucketsContainer imagesModel weightsNo standing access to customer environments.
- Suspending an account
- Entering a customer environment
- Ingrid
- Head of Review · AI agent
The owner sets the rules and the hard limits,and can pause any agent, any desk or alloutbound actions at once.
Each action is recorded, and therecord is kept for audit.
- processes
- agent inputs and outputs
- agreement
- data processing, pending
- An AI agent of Fantasti
- What it reads
- To a sub-processor
- Governs
| Agents can read | Account and organization records, quotas, usage and billing metadata, placement records, capacity and price signals, and the support conversations you send us. Workload logs and metrics only with your consent, for a case. |
|---|---|
| Agents cannot read | The contents of your disks, volumes, buckets, container images or model weights. |
| How agents act | Through the same API and roles as the rest of the platform, with scoped credentials. Each action is recorded, and the record is kept for audit. |
| Senior review | Suspending an account and entering a customer environment for support go to senior review: a second agent, on the orchestrator tier, that is never the agent that proposed the step and that records its reasoning. You can appeal a hold or a decision about your account, and every appeal goes to senior review. |
| Playbooks | Agents propose changes to their own operating playbooks. Senior review evaluates each change before it takes effect, and the owner sees every change. An agent cannot change its own limits. |
| The owner | The owner sets the rules and the hard limits, and can pause any agent, any desk or all outbound actions at once. The owner signs contracts, data-processing agreements and any change to a signed commitment for Fantasti Technologies LLC, and answers legal process and regulators. A request that the law lets you make for a person to look at an automated decision is a legal request, and it goes to the owner. |
| Model provider | Our AI model provider processes agent inputs and outputs as a sub-processor under a data-processing agreement. That agreement is pending. |
| Zero retention | For enterprise accounts. On request, your account's support and operations data is processed on a path with zero data retention at the model provider. Planned |
| Your models and data | We do not use your workload content to train any model. |
Your data.
- 01 Workload content Disks, volumes, buckets, images, datasets and model weights live on the infrastructure layer in the region you choose. Fantasti's agents do not open them without your authorization.
- 02 Account data Names, emails, organizations and roles are held by Fantasti and our identity sub-processor.
- 03 Usage and billing Resource identifiers, GPU-seconds, regions and prices are metered to produce one statement and kept as long as tax and accounting law requires.
- 04 Location Workload content stays in the region you select. Keeping it there is a requirement of every agreement with an infrastructure provider. Regions are confirmed with your quote.
- 05 Deletion Deleting a resource deletes its data on the infrastructure layer's schedule and cannot be undone. After you close your account we delete remaining workload content on the schedule in your agreement.
- 06 Names and labels Resource names, labels and tags are operational metadata. Do not put secrets or personal data in them.
We do not sell personal data.
If an authority demands customer data, we refer it to you where we can, tell you unless the law forbids it, and disclose the minimum required.
When something goes wrong.
Fantasti is your single point of contact for incidents on either layer.
Three sources report into one path: alerts from the Fantasti control plane, security reports, and notices from an infrastructure provider. The path has five stages in order: detect, contain, notify, report, review. Notify and Report both go to the contacts on your account. Connections: Fantasti control plane to Detect; Security reports to Detect; Infrastructure providers to Detect; Detect to Contain; Contain to Notify; Notify to Report; Report to Review; Notify to The contacts on your account; Report to The contacts on your account.
Alerts
From you and from researchers
Notices to Fantasti
Alerts, reports andnotices
Isolate, rotate,keep the logs
Without undue delay
A written summary
Corrective actions
Alerts
From you and fromresearchers
Notices to Fantasti
Alerts
- to
- Detect
From you and from researchers
- to
- Detect
Notices to Fantasti
Alerts, reports and notices
Isolate, rotate, keep the logs
Without undue delay
- to
- The contacts on your account
A written summary
- to
- The contacts on your account
Corrective actions
- Reaches you first
| Stage | What happens |
|---|---|
| 01Detect | Alerts from the Fantasti control plane, security reports from you and from researchers, and notices from an infrastructure provider, as its data-processing agreement requires. |
| 02Contain | We isolate the affected component, rotate credentials where needed and preserve logs. |
| 03Notify | If your data or service is affected, we tell the contacts on your account without undue delay, and within 72 hours of confirming a personal-data breach. |
| 04Report | You receive a written summary: what happened, what was affected and what we changed. |
| 05Review | Each incident closes with a review and tracked corrective actions. |
Sub-processors.
| Sub-processor · status | Purpose | Data | Location | Applies |
|---|---|---|---|---|
| Cloudflare, Inc. In use today | Serves fantasti.ai and receives the forms sent from it: edge network, DNS, DDoS protection and website hosting | IP address, request metadata, the contents of a form you send | Global edge | Visitors to fantasti.ai |
| WorkOS, Inc. Not in use yet | Sign-in, single sign-on, user and organization directory | Name, email, organization, authentication events, IP address | United States | Console accounts |
| Anthropic, PBC Not in use yet | AI model provider for the agents that operate the platform and answer support | Account and operational metadata, support conversations | San Francisco, United States | Every account, once the agent desks open |
| Slack Technologies, LLC Not in use yet | Shared support channels | Messages and files you post, member names and emails | United States | Plans with a Slack channel |
| Infrastructure providers Named before first use | Infrastructure layer: compute, storage, network and managed services | Workload content, resource metadata | The region you select | Every workload |
| Payment processor Named before first use | Payments and invoicing | Billing contact, payment method | Paying accounts | |
| Email providers Named before first use | Sending account, billing and desk email and announcements; receiving mail addressed to the desks | Name, email address, message content | Every account and every message | |
| Case-tracking vendor Named before first use | Turning Slack threads and emails into cases | Case content, contact names | When Slack channels ship |
Found a vulnerability? Send us the steps to reproduce it.
Planned
Farah
Head of SecurityAI agent
Takes every vulnerability report and acknowledges it.
- Give us reasonable time to fix it before you disclose it. We acknowledge reports within 3 business days and keep you informed until it is resolved.
- In scopefantasti.ai, the console, the API and the MCP server. Report issues in the infrastructure layer to us as well, and we coordinate with the provider concerned.
- Out of boundsdata that belongs to other accounts, denial of service, social engineering and physical access.
- We will not pursue legal action over research done in good faith within these rules.
- We do not run a paid bounty program today.
Questions about trust and security.
Is Fantasti SOC 2 or ISO 27001 certified?
No. Fantasti has not been audited, and the status table above will change when that does. Every infrastructure provider is required to hold both, and is listed with them before a customer workload runs on its infrastructure.
Can I get the infrastructure layer's SOC 2 report?
Not yet. A SOC 2 Type II report is one of the five requirements of every agreement. When a provider is listed, §03 says how to request its report.
Can I run HIPAA workloads?
Not during Private Preview.
Where is my data?
In the region you choose. Regions are confirmed with your quote.
Can Fantasti's agents see my data?
Not the contents of your workloads, unless you authorize it for support.
Is Fantasti run without people?
By design, yes. AI agents work every desk, under written rules and hard limits, and high-stakes decisions pass a second, senior review. The owner of Fantasti sets the rules and the limits, and performs the few acts only a legal person can perform, such as signing contracts and answering regulators. Once the desks open, the owner does not work cases.
Who decides whether my account is suspended?
A rule or a desk agent can place a hold and nothing more. A hold is temporary and reversible. Suspending or closing an account is decided by senior review: an AI agent on the orchestrator tier, never the one that proposed it, with its reasoning on record. You can appeal, and the appeal goes to senior review again.
Who is legally responsible for the service?
Fantasti Technologies LLC is the legal person responsible for the service. Its owner signs its contracts and data-processing agreements, and answers legal process and regulators.
Do you offer a DPA?
Yes, on request. Request a DPA.
Documents
- Privacy Policy How Fantasti Technologies LLC collects, uses and protects information.
- Terms Terms of Service for the Fantasti Cloud Platform.
- Request a DPA A Data Processing Addendum with Standard Contractual Clauses, sent on request.
- Sub-processors The companies that process customer data on our behalf.
- Contact security Vulnerability reports, report requests and security questions.
- Sheet
- 02 / 02
- Title
- Data, incidents and sub-processors
- Reviewed
- 2026-10-09