Security & compliance
Enterprise Grade Security for AI Customer Support
Audited controls, encrypted everywhere, region-pinned data and zero training on your content. Compliance is the floor, not the ceiling.
SOC 2 Type II
Independently audited annually.
GDPR
EU data residency and DPA on request.
HIPAA
BAA available on Enterprise plan.
ISO 27001
In progress · Q3 2026.
SSO + SCIM
Okta, Google, Azure AD, custom SAML.
Region pinning
Choose EU or US data residency.
Principles
How we think about security.
Four non-negotiables that shape every product decision and every line of code.
Your data is yours
We never train shared or third-party models on your content. Period.
Encrypted everywhere
AES-256 at rest. TLS 1.3 in transit. Per-tenant encryption keys on Enterprise.
Least privilege
RBAC, audit logs and time-bound staff access required for every internal action.
Resilient by design
99.9% uptime SLA, multi-region failover and continuous backup.
Compliance status & evidence
Every claim below is backed by documentation we will share under NDA.
| Framework | Status | Evidence |
|---|---|---|
| SOC 2 Type II | Certified | Full audit report available under NDA — request from [email protected]. |
| GDPR | Compliant | EU data residency option and signed DPA available on request. |
| HIPAA | BAA on Enterprise | Sign a Business Associate Agreement before sending any PHI. |
| ISO 27001 | In progress · Q3 2026 | Certification scope covers all production systems; updates published here. |
Data handling & encryption
Where your content lives, how it is protected, and how to get rid of it.
- AES-256 encryption at rest; TLS 1.3 for every connection in transit.
- Your content is stored in an isolated, per-tenant namespace — never co-mingled.
- Automatic PII redaction before content reaches model providers.
- Configurable retention: delete source documents and embeddings at any time.
- Data residency pinning: choose EU (Frankfurt) or US (Virginia) storage regions.
Access control
Identity, roles, and auditability for your team — and ours.
- SSO via Okta, Google Workspace, Azure AD, or custom SAML; SCIM provisioning on Enterprise.
- Role-based access control with granular viewer / editor / admin roles.
- Full audit log of every workspace action, exportable to your SIEM.
- Time-bound, least-privilege access required for all internal staff operations.
AI guarantees
What our agent will and won't do with your content.
- Answers are grounded strictly in your indexed content — never general model knowledge.
- Every answer can include citations back to the source document and passage.
- When confidence is low, the agent says so or escalates to a human instead of guessing.
- Your data is never used to train shared or third-party models.
Availability
99.9%
Uptime SLA
Multi-region
Failover ready
Hourly
Backups, tested
Enterprise onboarding
A four-step path from procurement sign-off to production rollout.
- 1
Kickoff & scoping
A solutions engineer maps your sources, volumes, and compliance requirements.
- 2
Security review
We complete your vendor questionnaire and provide SOC 2 report, DPA, and pen-test summary.
- 3
Pilot deployment
Train agents on a scoped content set and validate answer quality with your team.
- 4
Production rollout
SSO, RBAC, monitoring, and integrations configured — go live with SLA coverage.
Security questions?
Reach our security team for reports, documentation, or vulnerability disclosure at [email protected]. See also our privacy policy.
FAQ
Frequently asked questions
Is UnifiedRAG secure?
Yes. UnifiedRAG is built with enterprise-grade security practices to help protect customer data and AI interactions.
Is UnifiedRAG SOC 2 compliant?
Yes. UnifiedRAG follows SOC 2 Type II security and compliance standards.
Is UnifiedRAG GDPR compliant?
Yes. UnifiedRAG supports GDPR-compliant data practices to help businesses protect and manage customer information.
Is UnifiedRAG HIPAA compliant?
Yes. UnifiedRAG supports HIPAA-compliant use cases for organizations that require healthcare data protection.
Does UnifiedRAG use customer data to train AI models?
No. Customer content is not used to train shared AI models.
Build an AI Chatbot for Your Website in Minutes
Train your AI agent in minutes. Deploy to your site with one line of code. Watch deflection rates climb from day one.