路墨(Lumoswitch) provides multi-model inference management. This page sets out verifiable boundaries for access keys, upstream credentials, invocation observation, privacy, and data retention to support your integration decision.
The mainland China edition of Lumoswitch is operated by 泉州丰泽哈基科技有限公司. It provides model integration, control-plane routing, Access Keys, limits, usage accounting, and invocation observation; it is not a foundation-model provider and does not control third-party model prices, availability, or output.
02 · Credential boundary
Client keys are separate from upstream credentials
Clients use Lumoswitch Access Keys; administrators configure model-provider credentials in the control plane. Sensitive upstream credentials are stored encrypted and their complete plaintext is not shown again. Applications can use separate keys with scope and rate controlled by model configuration.
03 · Invocation observation
Runtime metadata helps investigate issues
Ordinary invocation records observe runtime metadata such as request time, model, status, latency, tokens, usage, and cost. Complete prompts and response bodies are not written to ordinary invocation logs by default. Actual processing follows the privacy policy and deployment.
04 · Account security
Rotate, revoke, and investigate
Access Keys can be independently rotated and revoked. The platform records necessary sign-in, account, and key security activity. If exposure is suspected, revoke or rotate the affected key first, then inspect invocation logs and billing.
Data-processing boundary
Where are requests sent?
When you select a third-party model provider, requests are sent to that provider as configured. Choosing a provider located abroad or one that may process data abroad can involve cross-border transfer. To avoid this, choose providers and regions processing data domestically and review their policies.
Published documents
Where are the complete rules?
The privacy policy covers information categories, purposes, third-party models, and cross-border processing. Data retention and deletion rules cover invocation, audit, account closure, and backup boundaries; terms cover accounts, third-party services, fees, and liability.
This public page does not promise certification, a fixed SLA, absolute security, that data never leaves a country, or perpetual availability of third-party models. Confirm enterprise data regions, retention periods, or security addenda through an order, DPA, or other written agreement.