Trust starts with an accurate data flow.
MUSCLE Flex is a managed cloud service. Requests can include prompts, source code, tool schemas, tool results and generated output. Adhibita processes that data to provide, secure, support and bill the service, and sends the request content a reply needs to the selected model provider.
Where a request goes.
- Step 1
Your application
Sends a request with a Flex key.
- Step 2
Flex edge
Checks the key, rate limits, request shape and available credits.
- Step 3
Routing decision
Excludes routes that cannot meet hard requirements, then picks one.
- Step 4
Selected model provider
Receives the request content needed to produce the reply.
- Step 5
Response and usage
Flex returns the reply, meters usage and settles the charge.
Controls in place.
What the beta does today, as documented for the deployed service.
Invite-only accounts
There is no public sign-up during the beta. Accounts are created from accepted invitations.
Keys you can revoke
You create and revoke Flex API keys in the portal. Flex stores a one-way hash of each key rather than the key itself; account summaries show only its last four characters. A revoked key is refused with 401.
Keys stay in headers
A request body with a field named like a credential or session token is rejected with 400. Send the key only in the documented header.
Spending stops at your balance
Charged requests need available prepaid credits. Without them the request is declined with 402 before any route is called. Per-key, per-account and per-IP rate limits apply.
Your tools run on your side
Flex returns tool calls to your application and never executes them. Hosted server-side tools are not offered in the beta, and Responses requests are stateless: Flex does not store responses for later retrieval.
Request IDs for every response
Each response carries an X-Request-Id header. Support uses it to find a request, so you never need to send prompts or keys to get help.
Categorical routing records
The records Flex keeps for routing and product learning are designed to be categorical rather than copies of code, prompts, file paths or identity. That does not make the inference request content-free: request content must still be processed to produce the reply.
Not yet published.
Subprocessors and retention
A subprocessor register and a retention schedule for request content, traces, account, billing and backup data are being prepared. Until they are published, ask support about a specific data class.
Certifications
Flex does not claim SOC 2, ISO 27001, HIPAA or any other certification, and the beta carries no availability SLA.
Report a security issue
Email [email protected] with the request ID and what you observed. Do not include API keys, private source code or customer data. The API reference documents authentication and error behavior in full.