Security & Compliance

We believe your documents belong to you, not to a corporation's AI training pipeline. That's why we built awRAG from the ground up with absolute data sovereignty, SOC 2 standards, and zero-compromise privacy.

100%
EU-Hosted
SOC 2
Standards
AES-256
Encryption
TLS 1.3
In Transit

Security & Compliance Certifications

SSL/TLS

Encrypted

GDPR

Compliant

EU Data

Storage

Encrypted

At Rest

SOC 2

Infrastructure

All data is stored exclusively in the European Union with industry-leading security standards

🇪🇺 100% European Data Storage

All your data stays exclusively within the European Union. We prioritize data sovereignty and GDPR compliance by hosting all infrastructure in EU data centers.

Database & Storage

PostgreSQL Database
EU Data Centers (Switzerland 🇨🇭)

Your documents, embeddings, and user data are stored securely in Switzerland's enterprise-grade data centers.

Application Hosting

Application Infrastructure
EU Data Centers (Finland 🇫🇮)

Our application runs on enterprise-grade infrastructure in Finland, ensuring low latency and high availability.

Verified Data Locations

Independently verifiable proof that all your data is stored in the European Union

🇨🇭

Switzerland (Zurich)

Database & File Storage

Region: eu-central-2
Certification: SOC 2 Type 2

How to verify:

  • • Check IP geolocation: Swiss data center
  • • DNS lookup confirms EU routing
  • • TLS certificate shows Swiss location
🇫🇮

Finland (Helsinki)

Application Hosting

Data Center: Helsinki Region
Certification: SOC 2 Type II, ISO 27001

How to verify:

  • • IP geolocation confirms Finland
  • • Server response headers show EU
  • • Latency tests confirm Nordic location

Independent Verification Tools

You can independently verify our data locations using these trusted third-party tools:

How to test: Use any of the tools above with our domain (awrag.io) or IP address to independently verify our EU data center locations. All results should confirm Switzerland and Finland locations.

GDPR-Compliant Data Storage & SOC 2 Security Standards

All data storage and backups remain exclusively in the European Union on SOC 2-certified infrastructure. The awRAG application is built with SOC 2 security standards including audit logging, access controls, and encryption. Document processing uses GDPR-compliant third-party services with EU-approved Standard Contractual Clauses for temporary embedding generation.

Built with SOC 2 Standards

At awRAG, data security comes first. That's why we don't just use SOC 2-certified infrastructure; the awRAG application itself is built strictly according to SOC 2 principles.

Application-Level Security Controls

  • ✓ Complete audit logging for all OAuth events
  • ✓ 90-day retention policy for security logs
  • ✓ Rate limiting to prevent brute-force attacks
  • ✓ Row Level Security (RLS) on all database tables

SOC 2-Certified Infrastructure

  • ✓ Database: SOC 2 Type 2 certified (Switzerland)
  • ✓ Hosting: SOC 2 Type II + ISO 27001 (Finland)
  • ✓ AI Processing: SOC 2 Type 2 certified
  • ✓ End-to-end encrypted data transmission

Data Encryption & Security

Encryption in Transit

All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols (HTTPS). This ensures that your documents and queries cannot be intercepted during transmission.

  • ✓ TLS 1.3 encryption
  • ✓ 256-bit SSL certificates
  • ✓ Secure WebSocket connections
  • ✓ HTTPS-only policy (no insecure HTTP)

Encryption at Rest

Your documents, vector embeddings, and personal data are encrypted when stored in our databases using AES-256 encryption. This protects your data even in the unlikely event of physical server access.

  • ✓ AES-256 database encryption
  • ✓ Encrypted file storage
  • ✓ Encrypted backups
  • ✓ Secure key management

Access Controls

Strict Row Level Security (RLS) policies ensure complete data isolation. Your documents and queries are accessible only to you - not to other users, not even to our team without explicit authorization.

  • ✓ Row Level Security (RLS) policies
  • ✓ Multi-tenant data isolation
  • ✓ Secure authentication (Supabase Auth)
  • ✓ Role-based access control (RBAC)

Authentication Security

We use industry-standard authentication practices to protect your account from unauthorized access. Passwords are hashed using bcrypt, and we support secure session management.

  • ✓ Bcrypt password hashing
  • ✓ Secure session tokens
  • ✓ CSRF protection
  • ✓ Email verification

GDPR Compliance

awRAG is fully compliant with the General Data Protection Regulation (GDPR), the EU's comprehensive data protection law. We are committed to protecting your privacy rights and ensuring transparent data processing.

Your Rights

  • • Right to access your data
  • • Right to rectification
  • • Right to erasure
  • • Right to data portability
  • • Right to object
  • • Right to withdraw consent

Our Commitments

  • • Transparent data processing
  • • Data minimization principle
  • • Purpose limitation
  • • Storage limitation
  • • Lawful processing basis
  • • Data breach notification

Technical Measures

  • • Privacy by design
  • • Privacy by default
  • • Pseudonymization
  • • Encryption standards
  • • Access logging
  • • Security monitoring

For detailed information about our GDPR compliance practices and your data rights, please refer to our Privacy Policy.

Infrastructure Security & Application Controls

Security at awRAG operates on two levels: SOC 2-certified infrastructure providers and application-level security controls built according to SOC 2 principles. This dual-layer approach ensures comprehensive protection for your data.

Database Infrastructure (SOC 2 Type 2 Certified)

Our database and authentication infrastructure is built on enterprise-grade, SOC 2-certified cloud services:

  • • PostgreSQL Database: Industry-leading relational database with advanced security features
  • • EU Data Centers: Switzerland location with ISO 27001, SOC 2 Type 2, and PCI DSS certifications
  • • Automated Backups: Regular backups ensure data resilience and disaster recovery
  • • DDoS Protection: Enterprise-grade protection against distributed denial-of-service attacks
  • • Network Isolation: Advanced network security ensuring complete data isolation
  • • Application Controls: Row Level Security (RLS) policies on all tables for multi-tenant data isolation

Application Hosting (SOC 2 Type II + ISO 27001 Certified)

Our application is hosted on enterprise-grade, SOC 2-certified infrastructure in the European Union:

  • • EU Data Centers: Finland location with SOC 2 Type II + ISO 27001 certifications
  • • High-Performance Storage: Ultra-fast SSD storage for optimal performance
  • • 99.99% Uptime SLA: Enterprise-grade reliability and availability
  • • Redundant Infrastructure: Multiple layers of redundancy prevent data loss
  • • Real-time Monitoring: 24/7 monitoring ensures rapid incident response
  • • Application Controls: OAuth audit logging with 90-day retention for security compliance

AI Processing Security (100% GDPR Compliant)

We use third-party AI services for vector embeddings and reranking services with full GDPR compliance:

  • • 100% GDPR Compliant: Protected by Data Processing Agreements (DPA) with EU-approved Standard Contractual Clauses (SCCs)
  • • Secure API Communication: All data sent to our AI partners is encrypted in transit using TLS 1.3
  • • No Model Training: Your data is never used to train AI models or retained beyond processing
  • • Temporary Processing Only: Document data is processed and immediately discarded - not stored by third parties
  • • Transfer Impact Assessment: Our AI partners conduct TIAs to ensure EU data protection standards
  • • SOC 2 Type 2 Certified: All AI partners meet enterprise security and compliance standards

Security Monitoring & Incident Response

Continuous Monitoring

We maintain 24/7 security monitoring to detect and respond to potential threats:

  • ✓ Real-time threat detection
  • ✓ Anomaly detection and alerting
  • ✓ Access logging and audit trails
  • ✓ Intrusion detection systems
  • ✓ Regular security scans and audits

Incident Response

In the unlikely event of a security incident:

  • ✓ Immediate incident containment and mitigation
  • ✓ Notification to supervisory authority within 72 hours (GDPR requirement)
  • ✓ User notification if high risk to rights and freedoms
  • ✓ Forensic analysis and root cause investigation
  • ✓ Implementation of corrective measures

Third-Party Service Providers

We carefully select and vet all third-party service providers to ensure they meet our security and privacy standards. All processors are bound by Data Processing Agreements (DPAs) as required by GDPR.

Service ProviderPurposeData LocationCompliance
Cloud InfrastructureDatabase, Auth, Storage🇨🇭 Switzerland (EU)SOC 2, ISO 27001, GDPR
Application HostingWeb Application🇫🇮 Finland (EU)SOC 2 Type II, ISO 27001, GDPR
AI Processing ServicesVector Embeddings & Reranking (100% GDPR Compliant)🇺🇸 USA (Temporary processing only)SOC 2 Type 2, GDPR DPA + SCCs

* Third-party AI services process document data temporarily for embedding generation only with 100% GDPR compliance (DPA + EU-approved SCCs). Embeddings are stored in EU data centers (Switzerland). Data is never retained by third-party AI services.

Data Portability & User Control

No Vendor Lock-in

Unlike other platforms, awRAG is built on the principle of data freedom. You maintain full control over your data at all times:

Export Your Data

  • ✓ Download all your documents anytime
  • ✓ Export vector embeddings in standard formats
  • ✓ Access query history and conversation logs
  • ✓ Machine-readable data formats (JSON, CSV)

Delete Your Data

  • ✓ Delete individual documents or entire projects
  • ✓ Request complete account deletion (GDPR right to erasure)
  • ✓ Data deletion within 90 days of request
  • ✓ Permanent deletion from backups

Responsible Disclosure

We take security vulnerabilities seriously and appreciate the security research community's efforts to keep awRAG secure.

Report a Security Vulnerability

If you discover a security vulnerability in awRAG, please report it responsibly:

  • • Email us at contact@awrag.io with "Security Vulnerability" in the subject line
  • • Provide detailed information about the vulnerability and steps to reproduce
  • • Allow us reasonable time to address the issue before public disclosure
  • • We commit to acknowledging your report within 48 hours

We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure and will acknowledge security researchers who help keep awRAG secure.

Contact Our Security Team

For security-related questions, concerns, or to request our Data Processing Agreement (DPA), please contact:

awRAG.io - Security & Compliance
Muhammed Alp
Gelderblomstr 73, 47138 Duisburg, Germany
Email: contact@awrag.io

Last Updated: November 1, 2025 | Privacy Policy | Terms of Service | Cookie Policy