Skip to content

Trust & Data Handling

raia Trust Center

A summary of how raia processes, stores, and protects customer data — the subprocessors involved, which of them provide LLM access, how long data is retained, and the policies that govern it. Signed policy documents and the complete subprocessor register are published below in Key Documents.

Key Documents

24 active policies · Last reviewed: August 2026 · SOC 2 Type II · GDPR compliant

Data

01

Data Processors

Third-party subprocessors used to deliver the raia platform. Each is reviewed under the Vendor Management Policy, and their security documentation is re-checked on a regular cadence.

SubprocessorPurposeDocumentation
Google CloudCloud infrastructure and hostingSecurity
AWSCloud infrastructure and hostingSecurity
CloudflareCDN, DNS, TLS, WAF and edge securitySecurity
SupabaseApplication database and storageSecurity
OpenAILLM inferenceSecurity
OpenRouterLLM gateway to additional model providersSecurity
TwilioSMS and voice channelsSecurity
MailgunTransactional and agent email deliverySecurity
StripeBilling and paymentsSecurity
GrafanaMonitoring, logging and alertingSecurity
n8nWorkflow automationSecurity
GitHubSource control and CI/CDSecurity
LovableDocumentation site hostingSecurity
02

LLM Processors

Only the processors below receive prompt or conversation content for model inference. raia holds enterprise agreements with both.

OpenAI

Enterprise agreement

Primary LLM inference provider

  • No training of any model on raia or customer data
  • Zero Data Retention (ZDR) option available
  • Data residency options available
Provider documentation

OpenRouter

Enterprise agreement

Model gateway to additional LLM providers

  • No training of any model on raia or customer data
  • Zero Data Retention (ZDR) option available
  • Data residency options available
Provider documentation

No training on customer data

raia's enterprise agreements with OpenAI and OpenRouter contractually prohibit training or fine-tuning any model on raia or raia customer data. Both providers also offer a Zero Data Retention option — prompts and completions are not persisted after the request is served — and data residency options for organizations with regional processing requirements. To request ZDR or a specific residency configuration, contact r+privacy@raiaai.com.
03

Processing Categories

SubprocessorPurposeCategories of data processed
CloudflareCDN, DNS, TLS termination, DDoS protection, web application firewall, bot management, and edge security for public raia properties.IP addresses; request headers; TLS metadata; cached static content; bot and threat scores; limited request logs used for security and performance analytics.
GrafanaInfrastructure monitoring, application performance dashboards, log aggregation, and alerting.Application and system logs; metrics and telemetry; account identifiers; IP addresses; error traces; performance and latency data.

Customer data sent through raia agents is not routed to Cloudflare or Grafana for processing unless it appears in a log, metric, or security event generated by the platform. Model processing is performed only by the LLM processors listed above.

04

Retention & Deletion

Administrators configure agent memory and chat-history retention to 30, 60, or 90 days, supporting data-minimization requirements. Retention and disposal are governed by the Data Retention and Disposal Policy.

ControlBehavior
Configurable retentionAgent memory and chat history retained for 30, 60, or 90 days as set per organization.
Shared memoryStored information is accessible across all users of an agent — suited to general FAQs.
Personal memoryInformation is stored and recalled per individual user, enforcing memory privacy between users of the same agent.
ExportConversation logs export via CSV or stream to external systems through webhooks.
Deletion requestsData subject deletion and export requests are supported under the Privacy and Data Protection Policy.
05

Data Policies

The policies below govern classification, retention, privacy, and processing integrity. Full text for each is published further down this page.

Security

Policies governing information security, network security, encryption, and incident response.

Operations

Business continuity, disaster recovery, and vendor management policies.

Governance

Organizational governance including change management, code of conduct, and risk assessment.

Privacy & Data

Data classification, retention, privacy protection, and processing integrity policies.

EU Information

European regulatory readiness, DORA, EU AI Act, and data-residency support for EU customers.

Certifications

StandardPosture
SOC 2 Type IIIndependent audits verify security, availability, and processing-integrity controls.
GDPRSupports data subject rights — including deletion and export — and maintains data processing agreements.
HIPAAHIPAA-compliant infrastructure with signed Business Associate Agreements for healthcare customers.

Contact