The principles that govern how Regurai operates.
Trust is not a feature. It is embedded in how Regurai is designed, operated, monitored, and continuously improved.
Security First
Defence-in-depth across identity, application, data, and infrastructure layers.
Responsible AI
Risk-based deployment, human oversight, and explainability where practicable.
Transparency
Clear documentation of practices, controls, subprocessors, and updates.
Customer Control
Customers retain ownership of their data and decision rights over its use.
Operational Resilience
Monitoring, redundancy, and incident response designed for regulated workloads.
Layered controls across every surface.
Identity & Access
MFA enforcement, role-based access, least-privilege grants, session controls.
Data Protection
Encryption in transit and at rest, tenant isolation, field-level encryption.
Infrastructure Security
Hardened cloud baselines, network segmentation, vendor due diligence.
Application Security
Secure SDLC, input validation, server-only secret boundaries, threat modelling.
Monitoring & Reliability
Append-only audit logs, anomaly detection, circuit breakers, SLO tracking.
An operating model for AI you can defend.
Alignment with the frameworks that matter.
Alignment does not imply certification unless explicitly stated. Audited certifications, where applicable, will be published with issuing body and validity period.
The data lifecycle, governed end to end.
Lawful basis, purpose limitation, minimisation.
Documented purposes, role-based access.
Encryption, isolation, access controls.
Defined schedules per data category.
Secure deletion or anonymisation.
A defined lifecycle for security events.
Responsible Disclosure
Report suspected vulnerabilities or security concerns to security@regurai.com. We acknowledge reports within two business days and coordinate disclosure in good faith.
Updates that keep customers informed.
Policy Updates
Material changes to public-facing policies.
Security Notices
Notifications relevant to security posture.
Platform Updates
Significant capability or architecture changes.
Operational Notices
Status, maintenance, and reliability advisories.
Documentation for security reviews and procurement.
Available under mutual NDA. Submit a request and the Trust team will respond within two business days.
Security Overview
Control summary, encryption, identity, and monitoring practices.
Privacy Policy
Public summary of data handling and individual rights.
Data Processing Addendum
Standard DPA for customers and partners.
Architecture Summary
High-level platform and tenancy model.
Subprocessor Register
Current list of service providers and their roles.
AI Governance Statement
Responsible AI commitments and operating model.
ESG Policy
Environmental, social and governance commitments with maturity.
Need something for a security review?
Submit a single request — we'll bundle the relevant documentation for your team.
