Rigana AI

Security & Trust

⚠ Not legal advice. These are structural starting-point templates so the launch isn't blocked on a blank page. Have qualified counsel review and finalize before publishing — especially anything about jurisdiction, data-processing commitments, liability, and India's DPDP Act / any GDPR exposure. Bracketed […] items are decisions the owner/counsel must fill.

A plain-language page covering: tenant isolation, encryption posture, sub-processors, data location, audit logging, and "your data is never used to train third-party models" [if true]. Content firms up with the Track-B hardening work; publish a lightweight version at launch and expand.

At a glance

  • Tenant isolation — your organization's data is separated from other customers.
  • Encryption posture — [align with the Track-B hardening: at-rest encryption, tenant isolation].
  • Sub-processors — [Anthropic], [Railway], [Resend]. [Link a current sub-processor list.]
  • Data location — [Where data resides; any cross-border transfer basis.]
  • Audit logging — security-relevant events are recorded for reliability and investigation.
  • Model training — [State clearly if data is not used to train third-party models — recommended commitment.]

See also the Privacy Policy for collection, retention, and rights details.