Review Raq.com
for your organisation
See how data moves through the service, configure account controls and agree a pilot with your team. We can help with your security questionnaire and any additional requirements.
Understand each part of the data flow
Provider retention, workspace storage and an external assistant’s history are separate. Review each service used by the proposed workflow.
Your team or AI assistant
People sign in to their accounts. Connected assistants receive the data their authorised connection can access.
Review: identity, account scope and the assistant’s own processing terms.
Raq.com
Your saved work, account permissions and audit events. Application and database servers run in Germany and Finland.
Review: saved content, diagnostic logs, file storage and backup retention.
Selected model provider
Supported text and chat requests use provider Zero Data Retention routes by default. Owners can lock ZDR and select EU/EEA or US processing.
Review: selected model, region and permitted features.
Configure the account around the use case
Additional governance policies are opt-in and account-specific. An owner manages them under Settings, then Security. Verify the saved configuration before relying on it.
AVAILABLE CONTROLRequire organisation sign-in and two-factor authentication. Apply session limits.
CHECK IN YOUR PILOTA user without the required identity or completed authentication challenge cannot access the account.
AVAILABLE CONTROLRestrict a connection to one client, make it read-only and revoke access.
CHECK IN YOUR PILOTAllowed reads work. Writes, cross-client requests and revoked credentials are refused.
AVAILABLE CONTROLLock ZDR and supported processing to EU/EEA or US endpoints. Approve models, modules and suppliers.
CHECK IN YOUR PILOTUnavailable regional routes fail instead of switching to global processing. Incompatible features are unavailable under the relevant restrictions.
AVAILABLE CONTROLExclude prompt and response content from new diagnostic logs. Restrict shared links and AI web search.
CHECK IN YOUR PILOTInspect a new synthetic request’s log. Earlier logs, saved work and backups retain their separate handling.
AVAILABLE CONTROLOwner-approved partner management, time-limited staff access and optional approval for support access.
CHECK IN YOUR PILOTConfirm the named staff, expiry and revocation behaviour, with the client owner retaining control of security rules.
Core text and chat provider ZDR is on by default. AI processing uses global routing unless a region is selected. Standard AI diagnostic logs may contain prompts and responses for up to 60 days.
Agree a small pilot with clear checks
Use synthetic records in two client accounts. Pick a useful task and agree the expected access, actions and evidence with your IT lead.
Define the workflow
Name the users, data sources and permitted actions. Decide which assistants, Raq.com features and external services are included.
Verify the boundaries
Exercise allowed and refused requests. Check sign-in, account isolation, region restrictions, log content and connection revocation.
Record the decision
Review the results and remaining requirements. Agree responsibility for administration, incidents, reviews and any changes before wider use.
Microsoft 365 Copilot pilot
Health, care or other sensitive records
Evidence for your security review
Account evidence export
With client governance enabled, owners can inspect account activity, export the audit log as CSV and download a trust pack showing the account’s controls, connections and processing services.
The export describes configuration at that point in time. Use it alongside the pilot results and agreed processing terms.
Read about client governance ↗- Account policy and approved connections
- Processing services for the selected modules
- Audit events for allowed and refused requests
- Pilot results and outstanding actions
- Agreed responsibilities and operating terms
Illustrative checklist. Pilot results and contractual documents are prepared separately from the account export.

Vu AI Ltd is Cyber Essentials certified
Whole organisation · Valid to 21 September 2027 · Verify certificate
Bring us your additional requirements
Send the security questionnaire or the exact acceptance criteria. We’ll identify existing evidence and scope any further work with you.
Penetration testing and assurance
Vu, the team behind Raq.com, can scope application and AI workflow testing, remediation and retesting. If procurement requires an independent tester or specific accreditation, we can agree a suitable assessment.
Vu penetration testing ↗Microsoft governance or bespoke hosting
Vu can work with your IT team on Microsoft 365 governance or assess a private deployment for stricter hosting requirements. Any bespoke architecture is scoped separately from standard Raq.com hosting.
Microsoft 365 AI governance ↗Does an EU processing lock keep everything in the EU?
Can you help with our security questionnaire?
Review your first use case with us
Bring the task, the data it touches and the conditions your IT team needs to meet.