We believe your documents belong to you, not to a corporation's AI training pipeline. That's why we built awRAG from the ground up with absolute data sovereignty, SOC 2 standards, and zero-compromise privacy.
Encrypted
Compliant
Storage
At Rest
Infrastructure
All data is stored exclusively in the European Union with industry-leading security standards
All your data stays exclusively within the European Union. We prioritize data sovereignty and GDPR compliance by hosting all infrastructure in EU data centers.
PostgreSQL Database
EU Data Centers (Switzerland 🇨ðŸ‡)
Your documents, embeddings, and user data are stored securely in Switzerland's enterprise-grade data centers.
Application Infrastructure
EU Data Centers (Finland 🇫🇮)
Our application runs on enterprise-grade infrastructure in Finland, ensuring low latency and high availability.
Independently verifiable proof that all your data is stored in the European Union
At awRAG, data security comes first. That's why we don't just use SOC 2-certified infrastructure; the awRAG application itself is built strictly according to SOC 2 principles.
All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols (HTTPS). This ensures that your documents and queries cannot be intercepted during transmission.
Your documents, vector embeddings, and personal data are encrypted when stored in our databases using AES-256 encryption. This protects your data even in the unlikely event of physical server access.
Strict Row Level Security (RLS) policies ensure complete data isolation. Your documents and queries are accessible only to you - not to other users, not even to our team without explicit authorization.
We use industry-standard authentication practices to protect your account from unauthorized access. Passwords are hashed using bcrypt, and we support secure session management.
awRAG is fully compliant with the General Data Protection Regulation (GDPR), the EU's comprehensive data protection law. We are committed to protecting your privacy rights and ensuring transparent data processing.
For detailed information about our GDPR compliance practices and your data rights, please refer to our Privacy Policy.
Security at awRAG operates on two levels: SOC 2-certified infrastructure providers and application-level security controls built according to SOC 2 principles. This dual-layer approach ensures comprehensive protection for your data.
Our database and authentication infrastructure is built on enterprise-grade, SOC 2-certified cloud services:
Our application is hosted on enterprise-grade, SOC 2-certified infrastructure in the European Union:
We use third-party AI services for vector embeddings and reranking services with full GDPR compliance:
We maintain 24/7 security monitoring to detect and respond to potential threats:
In the unlikely event of a security incident:
We carefully select and vet all third-party service providers to ensure they meet our security and privacy standards. All processors are bound by Data Processing Agreements (DPAs) as required by GDPR.
| Service Provider | Purpose | Data Location | Compliance |
|---|---|---|---|
| Cloud Infrastructure | Database, Auth, Storage | 🇨🇠Switzerland (EU) | SOC 2, ISO 27001, GDPR |
| Application Hosting | Web Application | 🇫🇮 Finland (EU) | SOC 2 Type II, ISO 27001, GDPR |
| AI Processing Services | Vector Embeddings & Reranking (100% GDPR Compliant) | 🇺🇸 USA (Temporary processing only) | SOC 2 Type 2, GDPR DPA + SCCs |
* Third-party AI services process document data temporarily for embedding generation only with 100% GDPR compliance (DPA + EU-approved SCCs). Embeddings are stored in EU data centers (Switzerland). Data is never retained by third-party AI services.
Unlike other platforms, awRAG is built on the principle of data freedom. You maintain full control over your data at all times:
We take security vulnerabilities seriously and appreciate the security research community's efforts to keep awRAG secure.
If you discover a security vulnerability in awRAG, please report it responsibly:
We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure and will acknowledge security researchers who help keep awRAG secure.
For security-related questions, concerns, or to request our Data Processing Agreement (DPA), please contact:
awRAG.io - Security & Compliance
Muhammed Alp
Gelderblomstr 73, 47138 Duisburg, Germany
Email: contact@awrag.io
Last Updated: November 1, 2025 | Privacy Policy | Terms of Service | Cookie Policy