Trust & Data Handling
raia Trust Center
A summary of how raia processes, stores, and protects customer data — the subprocessors involved, which of them provide LLM access, how long data is retained, and the policies that govern it. Signed policy documents and the complete subprocessor register are published below in Key Documents.
Key Documents
24 active policies · Last reviewed: August 2026 · SOC 2 Type II · GDPR compliant
Data
Data Processors
Third-party subprocessors used to deliver the raia platform. Each is reviewed under the Vendor Management Policy, and their security documentation is re-checked on a regular cadence.
| Subprocessor | Purpose | Documentation |
|---|---|---|
| Google Cloud | Cloud infrastructure and hosting | Security |
| AWS | Cloud infrastructure and hosting | Security |
| Cloudflare | CDN, DNS, TLS, WAF and edge security | Security |
| Supabase | Application database and storage | Security |
| OpenAI | LLM inference | Security |
| OpenRouter | LLM gateway to additional model providers | Security |
| Twilio | SMS and voice channels | Security |
| Mailgun | Transactional and agent email delivery | Security |
| Stripe | Billing and payments | Security |
| Grafana | Monitoring, logging and alerting | Security |
| n8n | Workflow automation | Security |
| GitHub | Source control and CI/CD | Security |
| Lovable | Documentation site hosting | Security |
LLM Processors
Only the processors below receive prompt or conversation content for model inference. raia holds enterprise agreements with both.
OpenAI
Enterprise agreementPrimary LLM inference provider
- No training of any model on raia or customer data
- Zero Data Retention (ZDR) option available
- Data residency options available
OpenRouter
Enterprise agreementModel gateway to additional LLM providers
- No training of any model on raia or customer data
- Zero Data Retention (ZDR) option available
- Data residency options available
No training on customer data
Processing Categories
| Subprocessor | Purpose | Categories of data processed |
|---|---|---|
| Cloudflare | CDN, DNS, TLS termination, DDoS protection, web application firewall, bot management, and edge security for public raia properties. | IP addresses; request headers; TLS metadata; cached static content; bot and threat scores; limited request logs used for security and performance analytics. |
| Grafana | Infrastructure monitoring, application performance dashboards, log aggregation, and alerting. | Application and system logs; metrics and telemetry; account identifiers; IP addresses; error traces; performance and latency data. |
Customer data sent through raia agents is not routed to Cloudflare or Grafana for processing unless it appears in a log, metric, or security event generated by the platform. Model processing is performed only by the LLM processors listed above.
Retention & Deletion
Administrators configure agent memory and chat-history retention to 30, 60, or 90 days, supporting data-minimization requirements. Retention and disposal are governed by the Data Retention and Disposal Policy.
| Control | Behavior |
|---|---|
| Configurable retention | Agent memory and chat history retained for 30, 60, or 90 days as set per organization. |
| Shared memory | Stored information is accessible across all users of an agent — suited to general FAQs. |
| Personal memory | Information is stored and recalled per individual user, enforcing memory privacy between users of the same agent. |
| Export | Conversation logs export via CSV or stream to external systems through webhooks. |
| Deletion requests | Data subject deletion and export requests are supported under the Privacy and Data Protection Policy. |
Data Policies
The policies below govern classification, retention, privacy, and processing integrity. Full text for each is published further down this page.
Security
Policies governing information security, network security, encryption, and incident response.
Operations
Business continuity, disaster recovery, and vendor management policies.
Governance
Organizational governance including change management, code of conduct, and risk assessment.
Privacy & Data
Data classification, retention, privacy protection, and processing integrity policies.
EU Information
European regulatory readiness, DORA, EU AI Act, and data-residency support for EU customers.
Certifications
| Standard | Posture |
|---|---|
| SOC 2 Type II | Independent audits verify security, availability, and processing-integrity controls. |
| GDPR | Supports data subject rights — including deletion and export — and maintains data processing agreements. |
| HIPAA | HIPAA-compliant infrastructure with signed Business Associate Agreements for healthcare customers. |