New Describe a workflow. Raq.com builds it for you and runs it on autopilot. Try Automations free →
Multi AI Chat AI Team Comms Photoshoot AI Task Board Top 20 AI Consensus AI AI Image Lab AI Marketing Campaigns AI Time Tracker Voice Calls AI Social Scheduler AI Video Lab AI Automations AI Ask My Agent AI Orchestrator Custom Tools AI AI Decisions AI Web Previews E-Sign Website Build & Host AI Client Portal Help Desk Page Feedback CRM Arbiter AI Design Swarm AI Project Base Ghostwriter AI Pretty Docs AI Secure Send Market Intel AI AI Music Lab AI KPI Hub Site Uptime Page Watch Server Monitor Knowledge AI Render to Reality AI Vector Motion Lab AI AI Benchmarker AI Website Chatbox AI Co-Write File Drop Contract Auditor AI Spreadsheet AI Creative Review Priorities AI Compliance Tracker Anti-slop Writer AI Rewriter AI Brand Guidelines AI Screenshot Studio Design MCP AI Screen Recorder Background Remover AI Image Optimiser SEO & AEO Checker AI Transcribe AI Vocalise AI Email Signatures AI Personas AI Recall 280daily Journal Meal Planner AI Health Insights AI Nature Work Passkey Vault Form Builder AI Prompt Library AI Skill Library AI PDF Page Studio File Converter Diff Viewer Receipt Extractor AI Branded CV AI FinUK Short URL QR Generator OneDrive Search AI
Raq.com

Privacy & Security

Security for your team's work

Your workspace holds the work your team depends on. We protect it with encrypted connections, account permissions and monitored infrastructure. Text and chat AI use Zero Data Retention routes by default.

For client and regulated work, account owners can switch on stricter controls, including EU or US AI processing.

Cyber Essentials Certified

Certification

Cyber Essentials certified

Raq.com is built and run by Vu AI Ltd, certified across the whole organisation. Cyber Essentials is the UK government-backed scheme covering five technical controls that help protect against common online attacks.

Certificate holder
Vu AI Ltd, company 15766790
Certification body
The IASME Consortium Ltd
Scope
Whole organisation
Certified
21 September 2026, valid to 21 September 2027
Verify this certificate

Our certification covers firewalls, secure configuration, security update management, user access control and malware protection. About the scheme.

How we protect your workspace

The controls behind your account, your data and the service your team uses.

Encrypted connections and disks

HTTPS protects your connection to Raq.com. Our dedicated application and database servers use encrypted disks to protect stored data.

Workspace permissions

Account membership, roles and record permissions control access to your workspace. Audit logs record key account and security activity. AI connection permissions are separate from membership.

Two-factor authentication

Add an authenticator app in your profile settings for an extra check when signing in. Account owners can require it for everyone in the account.

Protected infrastructure

Cloudflare filters web traffic before it reaches the application. Origin access is restricted, and we maintain the servers with security updates.

European application hosting

Our application and database servers run on dedicated hardware in Germany and Finland. Our subprocessor list explains the external services used by individual features.

Monitoring around the clock

Automated checks watch server health and service availability, alerting our team when something needs attention.

Backups and recovery

Automated database backups and a second application server location support recovery if a server becomes unavailable.

UK company, clear data policies

Vu AI Ltd operates Raq.com from the UK. Our Privacy Policy sets out how we handle personal data, how long we keep it and how to exercise your rights.

Read our Privacy Policy and subprocessor list for data handling and processing locations.

Client governance

Stricter controls for client and regulated work

Some accounts hold a client's work, or sit in an IT partner's portfolio alongside other clients. Account owners can switch on stricter controls for that account under Settings, then Security.

These controls are off unless an owner turns them on, and they only apply to the account where they're saved. Every other account keeps working as it does today.

Two client accounts, one agent connection and a request Raq.com refused

Keep each client separate

Give each client its own account. An AI agent connection can be approved for one client only, agent runs can be kept inside that account, and agent requests that cross into another account are refused.

Raq.com checks the account every tool call targets, including queued automation steps and calls made inside other tools. The rule holds even when one person belongs to several client accounts, so the boundary doesn't depend on the agent choosing correctly.

Sign-in and sessions

Require two-factor authentication, or verified Google Workspace or Microsoft organisation sign-in. Set a maximum session length and an idle timeout, and sign everyone out when you need to.

Agent access you can take back

Make agents read-only, expire connections after a set number of days and remove a connection from the account's Security page. Removal stops access straight away, including tokens the assistant already holds.

Audit trail and evidence

The account audit log records sign-ins, security changes and agent tool use, including requests Raq.com refused. Filter it, export it as CSV and download a trust pack showing the account's controls, connections and processing services.

IT partner access

An IT partner can manage client accounts from its own account. The client's owner approves the link and any proposed policy. Partner staff get time-limited access and can't change the client's security rules. Raq.com support access can need the owner's approval too.

Approved tools and suppliers

Limit the account to approved modules and AI models, and block individual suppliers. Modules whose suppliers we haven't reviewed are refused while supplier limits apply. Features that can't honour a region or retention setting are switched off for that account rather than run outside it.

Sharing and AI logs

Turn off shared links, AI web search and support transcript emails. Keep prompt and response content out of new AI diagnostic logs, so they record the request details without the content.

How it works

How each type of AI handles your data

Text and chat AI

Core text and chat requests use Zero Data Retention (ZDR) endpoints by default. Raq.com enforces this when routing requests to an AI model. This describes provider retention, not Raq.com storage: standard AI diagnostic records may include prompts and responses for up to 60 days.

These routes require providers not to retain your prompts or responses, or use them for training. You can change this in your account's AI Privacy settings to access additional models.

Live web search is controlled separately. If enabled, search lookups for current public information may use standard provider routing instead of ZDR so the lookup can complete.

Account owners can also lock an account to Zero Data Retention and to EU/EEA or US processing.

Image and video generation

The provider receives your prompt, generation settings and any reference files needed for the request. We save generated files to Raq.com-managed storage after generation.

Providers may retain these inputs and outputs under their API terms. These tools have different retention arrangements from text and chat AI.

Voice synthesis and transcription

The provider receives the text or audio needed for your request. We save the results to Raq.com-managed storage. Retention depends on the service and its API terms.

We opt out of model training where the provider offers that option. Our Privacy Policy and subprocessor list explain the services involved.

AI processing region

Choose where AI processing happens

Text and chat AI use global routing by default. An account owner can lock an account to EU/EEA or US processing instead, and Raq.com then sends supported model requests only through endpoints in that region.

Any region

The default for every account. Each request goes to an available endpoint for the chosen model, wherever that endpoint runs.

EU / EEA only

Model requests go through EU/EEA endpoints. If a model has none, the request fails rather than falling back to a global route, and retries stay in the region.

United States only

The same rule with US endpoints, for teams whose contracts or clients call for US processing.

What the region lock covers

  • The prompts, files and responses in supported text and chat AI requests.
  • Retries and fallbacks, which stay inside the chosen region.
  • Features with their own AI route that can't stay in the region, which are switched off for the account.

What it doesn't change

  • Where your workspace is stored: our servers in Germany and Finland and European file storage.
  • Image, video and voice generation, which use their own providers. Block those suppliers for the account if they shouldn't be used.
  • Connected services, and the account and billing records our suppliers hold.
  • What an external AI assistant does with information once it has received it.

Model availability differs by region and changes as providers add endpoints. You can combine a region lock with a Zero Data Retention lock. Our subprocessor list shows where each service runs.

Data held by Raq.com

We store the content you save in your workspace and keep request logs for billing, reliability and troubleshooting. Provider Zero Data Retention applies to the AI provider's handling of a request, separately from this workspace storage.

Raq.com doesn't use your content to train AI models. Our Privacy Policy explains retention periods, deletion and your data rights.

Planning to use health or care records?

Talk to us before special-category data such as health or social care records goes into Raq.com. We'll agree the processing purpose, a data processing agreement and any supplier terms with you, alongside your own impact assessment. Security settings are one part of that, and they don't replace it.

A good first step is a trial with made-up records in two client accounts. Your team can see what an agent is allowed to do in each one, and what Raq.com refuses.

Governance questions

Will these controls change how my account works?
Not unless you switch them on. Each control is off until an account owner saves it, and it only applies to that account.
Does the EU setting keep all of my data in the EU?
It covers supported AI model processing. Your workspace is already hosted in Germany and Finland. Some services, including our network provider, operate globally, and the subprocessor list shows where each one runs.
Can Raq.com stop an AI assistant remembering what it has read?
No. Raq.com decides what an assistant can read or change in your account. Once the assistant has the information, its provider's terms apply, so use a separate conversation or environment for each client.
Can we see what agents did in a client's account?
Yes. With client governance on, the account audit log records each agent tool call next to people's activity. A refused request is logged in the account the agent tried to reach. You can filter the log and export it as CSV.

Security questions or concerns

Our team can help with supplier security reviews and questions about how Raq.com handles your data.

For a suspected vulnerability, include the affected page or feature and steps to reproduce it, without sharing passwords or other people's data. We'll acknowledge your report and keep you updated as we investigate.

Email our security team