Skip to main content
ReguraiRegurai
Trust Center
Legal
Regurai Trust Center · Version 1.0

Trust by Design.
Governance by Default.

Regurai helps organisations adopt and govern AI responsibly through transparent controls, secure architecture, and accountable operations — engineered for regulated environments where trust is non-negotiable.

Request Security Information Contact Trust Team
Responsible AI
Embedded
Privacy by Design
Embedded
Security Architecture
Embedded
Enterprise Ready
Embedded
A · Trust Principles

The principles that govern how Regurai operates.

Trust is not a feature. It is embedded in how Regurai is designed, operated, monitored, and continuously improved.

Security First

Defence-in-depth across identity, application, data, and infrastructure layers.

Responsible AI

Risk-based deployment, human oversight, and explainability where practicable.

Transparency

Clear documentation of practices, controls, subprocessors, and updates.

Customer Control

Customers retain ownership of their data and decision rights over its use.

Operational Resilience

Monitoring, redundancy, and incident response designed for regulated workloads.

B · Security Architecture

Layered controls across every surface.

Designed Against

Identity & Access

MFA enforcement, role-based access, least-privilege grants, session controls.

Designed Against

Data Protection

Encryption in transit and at rest, tenant isolation, field-level encryption.

Aligned

Infrastructure Security

Hardened cloud baselines, network segmentation, vendor due diligence.

Aligned

Application Security

Secure SDLC, input validation, server-only secret boundaries, threat modelling.

Under Assessment

Monitoring & Reliability

Append-only audit logs, anomaly detection, circuit breakers, SLO tracking.

C · AI Governance Framework

An operating model for AI you can defend.

AI Inventory

Centralised registry of AI systems, owners, and dependencies.

Risk Classification

Risk tiers aligned with NIST AI RMF and EU AI Act categories.

Policy Enforcement

Codified policies applied to model deployment and change.

Human Oversight

Approval gates, exception workflows, and accountable owners.

Monitoring

Drift, fairness, and operational signals tracked continuously.

Audit Evidence

Append-only trails supporting internal and external assurance.

D · Compliance & Standards

Alignment with the frameworks that matter.

ISO 27001
Information Security Management
Under Assessment
ISO 42001
AI Management System
Aligned
SOC 2
Trust Services Criteria
Planned
NIST AI RMF
AI Risk Management Framework
Aligned
NIST CSF
Cybersecurity Framework
Aligned
GDPR Principles
Lawful, fair, transparent processing
Designed Against
OWASP
Application Security Top 10
Aligned
Zero Trust
Identity-centric architecture
Designed Against

Alignment does not imply certification unless explicitly stated. Audited certifications, where applicable, will be published with issuing body and validity period.

E · Privacy & Data Governance

The data lifecycle, governed end to end.

01
Collection

Lawful basis, purpose limitation, minimisation.

02
Processing

Documented purposes, role-based access.

03
Protection

Encryption, isolation, access controls.

04
Retention

Defined schedules per data category.

05
Deletion

Secure deletion or anonymisation.

Read the full Privacy Policy
F · Incident Response

A defined lifecycle for security events.

Detect
Phase 1
Assess
Phase 2
Contain
Phase 3
Notify
Phase 4
Recover
Phase 5
Improve
Phase 6

Responsible Disclosure

Report suspected vulnerabilities or security concerns to security@regurai.com. We acknowledge reports within two business days and coordinate disclosure in good faith.

G · Transparency Hub

Updates that keep customers informed.

Policy Updates

Material changes to public-facing policies.

Available on request

Security Notices

Notifications relevant to security posture.

Available on request

Platform Updates

Significant capability or architecture changes.

Available on request

Operational Notices

Status, maintenance, and reliability advisories.

Available on request
H · Customer Assurance

Documentation for security reviews and procurement.

Available under mutual NDA. Submit a request and the Trust team will respond within two business days.

On request

Security Overview

Control summary, encryption, identity, and monitoring practices.

View

Privacy Policy

Public summary of data handling and individual rights.

On request

Data Processing Addendum

Standard DPA for customers and partners.

On request

Architecture Summary

High-level platform and tenancy model.

On request

Subprocessor Register

Current list of service providers and their roles.

View

AI Governance Statement

Responsible AI commitments and operating model.

View

ESG Policy

Environmental, social and governance commitments with maturity.

Need something for a security review?

Submit a single request — we'll bundle the relevant documentation for your team.

Request Security Information