Security & Legal

    Security at Raqi.io

    Enterprise-grade security and data protection for your business conversations.

    Your data security is our top priority. Here's how we protect it.

    Encryption in Transit

    All data transmitted to and from Raqi.io uses TLS 1.2 or higher. We enforce HTTPS across all endpoints and APIs.

    Encryption at Rest

    Database records and file storage are encrypted using AES-256 encryption. Backups are also encrypted.

    API Key Security

    API keys are hashed using SHA-256 before storage. Raw keys are displayed only once at creation and never persisted in plaintext.

    Authentication

    Secure authentication via Google OAuth and Supabase Auth. Support for two-factor authentication (2FA) via TOTP authenticator apps.

    Access Controls

    Role-based access control (RBAC) with workspace-level data isolation. Team members can have Admin, Manager, or Member roles.

    Infrastructure Security

    Backend runs in isolated Docker containers on Railway. Frontend served via Vercel's edge network with Cloudflare DNS and CDN.

    AI Data Handling

    AI providers (OpenAI, Anthropic) process data per their enterprise agreements. We do not use your data to train general-purpose AI models.

    Incident Response

    We maintain incident response procedures to promptly detect, investigate, and remediate security events. Users are notified of breaches that affect their data.

    Data Handling

    How we handle your data

    Messaging Data

    Stored encrypted in Supabase (US). Retained for the duration of your subscription. Deleted within 30 days of account termination.

    Access Tokens

    Channel access tokens (Meta, Telegram) are stored encrypted in our database. Never logged or exposed in API responses.

    AI Processing

    Conversation context sent to AI providers for real-time processing only. Not stored by AI providers beyond their standard API retention (typically 0–30 days).

    Media Files

    User-uploaded media stored in Supabase Storage with encrypted-at-rest buckets. Media URLs use signed tokens with expiration.

    Backups

    Automated daily database backups with point-in-time recovery. Backup data is encrypted and retained for 30 days.

    Compliance

    Regulatory compliance

    GDPR Ready

    Data processing agreements, user rights management, and EU Standard Contractual Clauses for international transfers.

    CCPA Compliant

    California Consumer Privacy Act compliance with right to know, delete, and opt-out mechanisms.

    Meta Platform Terms

    Full compliance with Meta Developer Policies for Instagram, Messenger, and WhatsApp data handling.

    SOC 2 (Infrastructure)

    Our infrastructure providers (Supabase, Vercel, Railway) maintain SOC 2 Type II certifications.

    Infrastructure

    Our infrastructure stack

    ProviderServiceLocationCertifications
    SupabaseDatabase, Auth, StorageUSSOC 2 Type II
    RailwayBackend hostingUSSOC 2 Type II
    VercelFrontend, CDNUS (edge)SOC 2 Type II
    CloudflareDNS, DDoS protectionGlobalSOC 2, ISO 27001
    OpenAIAI processingUSSOC 2 Type II
    AnthropicAI processingUSSOC 2 Type II
    StripePaymentsUSPCI DSS Level 1

    Report a Vulnerability

    If you discover a security vulnerability in Raqi.io, please report it responsibly. We take all reports seriously and will respond promptly.

    Report to info@raqi.io

    Raqi.io is a product of Ruwwad LLC.