Security at Raqi.io
Enterprise-grade security and data protection for your business conversations.
Your data security is our top priority. Here's how we protect it.
Encryption in Transit
All data transmitted to and from Raqi.io uses TLS 1.2 or higher. We enforce HTTPS across all endpoints and APIs.
Encryption at Rest
Database records and file storage are encrypted using AES-256 encryption. Backups are also encrypted.
API Key Security
API keys are hashed using SHA-256 before storage. Raw keys are displayed only once at creation and never persisted in plaintext.
Authentication
Secure authentication via Google OAuth and Supabase Auth. Support for two-factor authentication (2FA) via TOTP authenticator apps.
Access Controls
Role-based access control (RBAC) with workspace-level data isolation. Team members can have Admin, Manager, or Member roles.
Infrastructure Security
Backend runs in isolated Docker containers on Railway. Frontend served via Vercel's edge network with Cloudflare DNS and CDN.
AI Data Handling
AI providers (OpenAI, Anthropic) process data per their enterprise agreements. We do not use your data to train general-purpose AI models.
Incident Response
We maintain incident response procedures to promptly detect, investigate, and remediate security events. Users are notified of breaches that affect their data.
Data Handling
How we handle your data
Messaging Data
Stored encrypted in Supabase (US). Retained for the duration of your subscription. Deleted within 30 days of account termination.
Access Tokens
Channel access tokens (Meta, Telegram) are stored encrypted in our database. Never logged or exposed in API responses.
AI Processing
Conversation context sent to AI providers for real-time processing only. Not stored by AI providers beyond their standard API retention (typically 0–30 days).
Media Files
User-uploaded media stored in Supabase Storage with encrypted-at-rest buckets. Media URLs use signed tokens with expiration.
Backups
Automated daily database backups with point-in-time recovery. Backup data is encrypted and retained for 30 days.
Compliance
Regulatory compliance
GDPR Ready
Data processing agreements, user rights management, and EU Standard Contractual Clauses for international transfers.
CCPA Compliant
California Consumer Privacy Act compliance with right to know, delete, and opt-out mechanisms.
Meta Platform Terms
Full compliance with Meta Developer Policies for Instagram, Messenger, and WhatsApp data handling.
SOC 2 (Infrastructure)
Our infrastructure providers (Supabase, Vercel, Railway) maintain SOC 2 Type II certifications.
Infrastructure
Our infrastructure stack
| Provider | Service | Location | Certifications |
|---|---|---|---|
| Supabase | Database, Auth, Storage | US | SOC 2 Type II |
| Railway | Backend hosting | US | SOC 2 Type II |
| Vercel | Frontend, CDN | US (edge) | SOC 2 Type II |
| Cloudflare | DNS, DDoS protection | Global | SOC 2, ISO 27001 |
| OpenAI | AI processing | US | SOC 2 Type II |
| Anthropic | AI processing | US | SOC 2 Type II |
| Stripe | Payments | US | PCI DSS Level 1 |
Report a Vulnerability
If you discover a security vulnerability in Raqi.io, please report it responsibly. We take all reports seriously and will respond promptly.
Report to info@raqi.ioRaqi.io is a product of Ruwwad LLC.