Security & compliance

    Enterprise Grade Security for AI Customer Support

    Audited controls, encrypted everywhere, region-pinned data and zero training on your content. Compliance is the floor, not the ceiling.

    SOC 2 Type II

    Independently audited annually.

    GDPR

    EU data residency and DPA on request.

    HIPAA

    BAA available on Enterprise plan.

    ISO 27001

    In progress · Q3 2026.

    SSO + SCIM

    Okta, Google, Azure AD, custom SAML.

    Region pinning

    Choose EU or US data residency.

    Principles

    How we think about security.

    Four non-negotiables that shape every product decision and every line of code.

    • Your data is yours

      We never train shared or third-party models on your content. Period.

    • Encrypted everywhere

      AES-256 at rest. TLS 1.3 in transit. Per-tenant encryption keys on Enterprise.

    • Least privilege

      RBAC, audit logs and time-bound staff access required for every internal action.

    • Resilient by design

      99.9% uptime SLA, multi-region failover and continuous backup.

    Compliance status & evidence

    Every claim below is backed by documentation we will share under NDA.

    UnifiedRAG compliance frameworks, status, and evidence
    FrameworkStatusEvidence
    SOC 2 Type IICertifiedFull audit report available under NDA — request from [email protected].
    GDPRCompliantEU data residency option and signed DPA available on request.
    HIPAABAA on EnterpriseSign a Business Associate Agreement before sending any PHI.
    ISO 27001In progress · Q3 2026Certification scope covers all production systems; updates published here.

    Data handling & encryption

    Where your content lives, how it is protected, and how to get rid of it.

    • AES-256 encryption at rest; TLS 1.3 for every connection in transit.
    • Your content is stored in an isolated, per-tenant namespace — never co-mingled.
    • Automatic PII redaction before content reaches model providers.
    • Configurable retention: delete source documents and embeddings at any time.
    • Data residency pinning: choose EU (Frankfurt) or US (Virginia) storage regions.

    Access control

    Identity, roles, and auditability for your team — and ours.

    • SSO via Okta, Google Workspace, Azure AD, or custom SAML; SCIM provisioning on Enterprise.
    • Role-based access control with granular viewer / editor / admin roles.
    • Full audit log of every workspace action, exportable to your SIEM.
    • Time-bound, least-privilege access required for all internal staff operations.

    AI guarantees

    What our agent will and won't do with your content.

    • Answers are grounded strictly in your indexed content — never general model knowledge.
    • Every answer can include citations back to the source document and passage.
    • When confidence is low, the agent says so or escalates to a human instead of guessing.
    • Your data is never used to train shared or third-party models.

    Availability

    99.9%

    Uptime SLA

    Multi-region

    Failover ready

    Hourly

    Backups, tested

    Enterprise onboarding

    A four-step path from procurement sign-off to production rollout.

    1. 1

      Kickoff & scoping

      A solutions engineer maps your sources, volumes, and compliance requirements.

    2. 2

      Security review

      We complete your vendor questionnaire and provide SOC 2 report, DPA, and pen-test summary.

    3. 3

      Pilot deployment

      Train agents on a scoped content set and validate answer quality with your team.

    4. 4

      Production rollout

      SSO, RBAC, monitoring, and integrations configured — go live with SLA coverage.

    Security questions?

    Reach our security team for reports, documentation, or vulnerability disclosure at [email protected]. See also our privacy policy.

    FAQ

    Frequently asked questions

    Is UnifiedRAG secure?

    Yes. UnifiedRAG is built with enterprise-grade security practices to help protect customer data and AI interactions.

    Is UnifiedRAG SOC 2 compliant?

    Yes. UnifiedRAG follows SOC 2 Type II security and compliance standards.

    Is UnifiedRAG GDPR compliant?

    Yes. UnifiedRAG supports GDPR-compliant data practices to help businesses protect and manage customer information.

    Is UnifiedRAG HIPAA compliant?

    Yes. UnifiedRAG supports HIPAA-compliant use cases for organizations that require healthcare data protection.

    Does UnifiedRAG use customer data to train AI models?

    No. Customer content is not used to train shared AI models.

    7-day free trial · No credit card required

    Build an AI Chatbot for Your Website in Minutes

    Train your AI agent in minutes. Deploy to your site with one line of code. Watch deflection rates climb from day one.

    SOC 2 Type II
    GDPR compliant
    99.9% uptime SLA
    No credit card
    AI Chatbot Security & Data Privacy | UnifiedRAG — UnifiedRAG