Privacy & Security
Security for your team's work
Your workspace holds the work your team depends on. We protect it with encrypted connections, account permissions and monitored infrastructure. Text and chat AI use Zero Data Retention routes by default.
For client and regulated work, account owners can switch on stricter controls, including EU or US AI processing.
Certification
Cyber Essentials certified
Raq.com is built and run by Vu AI Ltd, certified across the whole organisation. Cyber Essentials is the UK government-backed scheme covering five technical controls that help protect against common online attacks.
- Certificate holder
- Vu AI Ltd, company 15766790
- Certification body
- The IASME Consortium Ltd
- Scope
- Whole organisation
- Certified
- 21 September 2026, valid to 21 September 2027
Our certification covers firewalls, secure configuration, security update management, user access control and malware protection. About the scheme.
How we protect your workspace
The controls behind your account, your data and the service your team uses.
Encrypted connections and disks
HTTPS protects your connection to Raq.com. Our dedicated application and database servers use encrypted disks to protect stored data.
Workspace permissions
Account membership, roles and record permissions control access to your workspace. Audit logs record key account and security activity. AI connection permissions are separate from membership.
Two-factor authentication
Add an authenticator app in your profile settings for an extra check when signing in. Account owners can require it for everyone in the account.
Protected infrastructure
Cloudflare filters web traffic before it reaches the application. Origin access is restricted, and we maintain the servers with security updates.
European application hosting
Our application and database servers run on dedicated hardware in Germany and Finland. Our subprocessor list explains the external services used by individual features.
Monitoring around the clock
Automated checks watch server health and service availability, alerting our team when something needs attention.
Backups and recovery
Automated database backups and a second application server location support recovery if a server becomes unavailable.
UK company, clear data policies
Vu AI Ltd operates Raq.com from the UK. Our Privacy Policy sets out how we handle personal data, how long we keep it and how to exercise your rights.
Read our Privacy Policy and subprocessor list for data handling and processing locations.
Client governance
Stricter controls for client and regulated work
Some accounts hold a client's work, or sit in an IT partner's portfolio alongside other clients. Account owners can switch on stricter controls for that account under Settings, then Security.
These controls are off unless an owner turns them on, and they only apply to the account where they're saved. Every other account keeps working as it does today.
Keep each client separate
Give each client its own account. An AI agent connection can be approved for one client only, agent runs can be kept inside that account, and agent requests that cross into another account are refused.
Raq.com checks the account every tool call targets, including queued automation steps and calls made inside other tools. The rule holds even when one person belongs to several client accounts, so the boundary doesn't depend on the agent choosing correctly.
Sign-in and sessions
Require two-factor authentication, or verified Google Workspace or Microsoft organisation sign-in. Set a maximum session length and an idle timeout, and sign everyone out when you need to.
Agent access you can take back
Make agents read-only, expire connections after a set number of days and remove a connection from the account's Security page. Removal stops access straight away, including tokens the assistant already holds.
Audit trail and evidence
The account audit log records sign-ins, security changes and agent tool use, including requests Raq.com refused. Filter it, export it as CSV and download a trust pack showing the account's controls, connections and processing services.
IT partner access
An IT partner can manage client accounts from its own account. The client's owner approves the link and any proposed policy. Partner staff get time-limited access and can't change the client's security rules. Raq.com support access can need the owner's approval too.
Approved tools and suppliers
Limit the account to approved modules and AI models, and block individual suppliers. Modules whose suppliers we haven't reviewed are refused while supplier limits apply. Features that can't honour a region or retention setting are switched off for that account rather than run outside it.
Sharing and AI logs
Turn off shared links, AI web search and support transcript emails. Keep prompt and response content out of new AI diagnostic logs, so they record the request details without the content.
How it works
How each type of AI handles your data
Text and chat AI
Core text and chat requests use Zero Data Retention (ZDR) endpoints by default. Raq.com enforces this when routing requests to an AI model. This describes provider retention, not Raq.com storage: standard AI diagnostic records may include prompts and responses for up to 60 days.
These routes require providers not to retain your prompts or responses, or use them for training. You can change this in your account's AI Privacy settings to access additional models.
Live web search is controlled separately. If enabled, search lookups for current public information may use standard provider routing instead of ZDR so the lookup can complete.
Account owners can also lock an account to Zero Data Retention and to EU/EEA or US processing.
Image and video generation
The provider receives your prompt, generation settings and any reference files needed for the request. We save generated files to Raq.com-managed storage after generation.
Providers may retain these inputs and outputs under their API terms. These tools have different retention arrangements from text and chat AI.
Voice synthesis and transcription
The provider receives the text or audio needed for your request. We save the results to Raq.com-managed storage. Retention depends on the service and its API terms.
We opt out of model training where the provider offers that option. Our Privacy Policy and subprocessor list explain the services involved.
AI processing region
Choose where AI processing happens
Text and chat AI use global routing by default. An account owner can lock an account to EU/EEA or US processing instead, and Raq.com then sends supported model requests only through endpoints in that region.
Any region
The default for every account. Each request goes to an available endpoint for the chosen model, wherever that endpoint runs.
EU / EEA only
Model requests go through EU/EEA endpoints. If a model has none, the request fails rather than falling back to a global route, and retries stay in the region.
United States only
The same rule with US endpoints, for teams whose contracts or clients call for US processing.
What the region lock covers
- The prompts, files and responses in supported text and chat AI requests.
- Retries and fallbacks, which stay inside the chosen region.
- Features with their own AI route that can't stay in the region, which are switched off for the account.
What it doesn't change
- Where your workspace is stored: our servers in Germany and Finland and European file storage.
- Image, video and voice generation, which use their own providers. Block those suppliers for the account if they shouldn't be used.
- Connected services, and the account and billing records our suppliers hold.
- What an external AI assistant does with information once it has received it.
Model availability differs by region and changes as providers add endpoints. You can combine a region lock with a Zero Data Retention lock. Our subprocessor list shows where each service runs.
Data held by Raq.com
We store the content you save in your workspace and keep request logs for billing, reliability and troubleshooting. Provider Zero Data Retention applies to the AI provider's handling of a request, separately from this workspace storage.
Raq.com doesn't use your content to train AI models. Our Privacy Policy explains retention periods, deletion and your data rights.
Planning to use health or care records?
Talk to us before special-category data such as health or social care records goes into Raq.com. We'll agree the processing purpose, a data processing agreement and any supplier terms with you, alongside your own impact assessment. Security settings are one part of that, and they don't replace it.
A good first step is a trial with made-up records in two client accounts. Your team can see what an agent is allowed to do in each one, and what Raq.com refuses.
Governance questions
- Will these controls change how my account works?
- Not unless you switch them on. Each control is off until an account owner saves it, and it only applies to that account.
- Does the EU setting keep all of my data in the EU?
- It covers supported AI model processing. Your workspace is already hosted in Germany and Finland. Some services, including our network provider, operate globally, and the subprocessor list shows where each one runs.
- Can Raq.com stop an AI assistant remembering what it has read?
- No. Raq.com decides what an assistant can read or change in your account. Once the assistant has the information, its provider's terms apply, so use a separate conversation or environment for each client.
- Can we see what agents did in a client's account?
- Yes. With client governance on, the account audit log records each agent tool call next to people's activity. A refused request is logged in the account the agent tried to reach. You can filter the log and export it as CSV.
Security questions or concerns
Our team can help with supplier security reviews and questions about how Raq.com handles your data.
For a suspected vulnerability, include the affected page or feature and steps to reproduce it, without sharing passwords or other people's data. We'll acknowledge your report and keep you updated as we investigate.
Email our security team