Trust Center
RAIA AI is committed to protecting your data and maintaining the highest standards of security and compliance. Browse our complete policy library to understand how we safeguard your information.
Key Documents
Stay informed on security updates
Get notified when we publish new audit reports, policy revisions, and security advisories.
Security
Policies governing information security, network security, encryption, and incident response.
Operations
Business continuity, disaster recovery, and vendor management policies.
Governance
Organizational governance including change management, code of conduct, and risk assessment.
Privacy & Data
Data classification, retention, privacy protection, and processing integrity policies.
Data Processors
Third-party subprocessors we use to deliver raia services, with links to their security and compliance documentation.
We perform due diligence on all subprocessors and review their security documentation regularly. For questions, contact us at r+privacy@raiaai.com.
EU Information
European regulatory readiness, DORA, EU AI Act, and data-residency support for EU customers.
Questions about our compliance?
If you have questions about our security practices, need a copy of our SOC 2 report, or require a Data Processing Agreement, please reach out to our team.
Contact UsPurpose and Scope
This Acceptable Use Policy defines standards for appropriate and secure use of raia’s hardware and electronic systems including storage media, communication tools and internet access. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans.
General
Ownership
raia is the owner of all company-issued hardware and electronic systems including the data stored in them or transmitted from them.
User Responsibilities
Personnel should not make any discriminatory, disparaging, defamatory or harassing comments when discussing raia. Discussing raia includes the use of social media, blogging or otherwise engaging in any conduct to the detriment of raia.
Personal Use Systems
Personal use of raia electronic systems is permitted provided such use does not interfere with productivity, confidentiality or the business and is not in conflict with team member responsibilities outlined in any raia policy.
Compliance
For security and network maintenance purposes, raia may monitor and track system access and content of raia hardware, system(s) and information to reasonably ensure compliance with applicable laws, regulations and raia policies.
raia reserves the right to access and audit any devices, networks and systems to ensure compliance with any raia policy.
Communication Tools
Use of Email and Messaging Tools
Email (e.g., Google Workspace, MailGun, SendGrid) and other messaging tools (e.g., Slack, Google Voice, Twilio) are intended to be used as business tools to facilitate communications and the exchange of information needed by team members to perform their assigned duties.
Encryption
All messages and/or attachments that contain confidential information are required to be encrypted to protect the privacy of the information.
Responsibilities
Passwords should not be shared with another individual. They are intended for the authorized team member only.
Team members who transmit confidential information outside the organization should comply with applicable regulatory requirements, customer requirements, and raia policies regarding the disclosure of confidential information to third parties.
Communications may be monitored and tracked without consent or advanced notice to the team member.
Retention and disposal of electronic communications should be in accordance with all raia data protection and privacy policies.
Prohibited Uses of Communication Tools
- Dissemination of confidential or protected information (i.e., trade secrets, team member personal information or financial data, customer information, etc.), except for approved business purposes.
- Attempting to gain access to another team member’s account, without permission.
- Misrepresenting, obscuring, suppressing, or replacing a team member’s identity.
- Sending confidential information over an open network (the Internet) without proper encryption.
- Transmitting, retrieving, or storing any communications or materials of a defamatory, discriminatory, harassing, or obscene nature.
- Transmitting messages with derogatory or inflammatory remarks about an individual's race, age, disability, religion, national origin, physical attributes or sexual preference.
Devices
Use of Company Devices
The use of raia phones (static and mobile), laptops and other hardware is primarily for business use.
Use of Personal Devices (BYOD)
The use of a personal device for raia purposes should be limited to email and the raia messaging tool unless there is business justification and formal approval. Personnel must not save raia data to any personal device. Personnel are responsible for configuring their device to be in alignment with the device configuration settings specified in the next section of this policy. Personal phones are not in scope for this policy.
Mobile Device Management (MDM)
Mobile device management (MDM) is implemented to manage and enforce mobile device configuration and security policies. Mobile devices must be approved prior to granting access to resources. raia utilizes Secureframe Agent for device monitoring.
The MDM solution should ensure and/or manage the following:
- Encryption: User endpoint storage is encrypted at rest (e.g., FileVault for macOS or BitLocker for Windows).
- Security Updates: OS security updates are enforced and monitored.
- Malware Protection: Malware protection is enabled (e.g., XProtect for macOS, Windows Defender for Windows).
- Screensaver / Lockscreen: Screensavers / lockscreens are configured to activate after a maximum of 15 minutes.
- Logging: Logs are captured and stored to assist with security investigations.
- Password Policy: Required passwords must align with raia's Access Control and Termination Policy.
- Firewall: Local firewall is enabled to provide layered host protection unless it interferes with development activities.
- Remote Wipe (Optional): In the event of employee departure or theft, the mobile devices can be remotely wiped.
Employees and applicable contractors must report loss, theft, or other security incidents related to their company-provided mobile device in a timely manner.
Use of Removable Media
raia personnel must only use approved removable media on their work computers. Sensitive information must only be stored on removable media only when required in the performance of assigned duties and upon management's approval. When sensitive information is stored on removable media, it must be encrypted in accordance with the raia Encryption and Key Management Policy. Exceptions to this requirement may be granted by senior management.
Responsibilities
Personal use of raia devices are allowed only as set forth in the General section of this policy.
Personnel assigned a raia device are responsible for protecting the device from theft or damage.
If the issued device is lost or stolen, personnel responsible for the device must report the loss or theft to r@raiaai.com.
Devices that have not been approved by management should not be used to send or store any confidential information.
Social Media
Limited and occasional use of raia devices to access social media is acceptable, provided that it is done in a professional and responsible manner, does not otherwise violate raia policies, is not detrimental to the best interests of raia, and does not interfere with a team members regular work duties.
Networks and Internet Access
Responsibilities
Use of internet access is primarily for business use. Personal use is allowed only as set forth in this policy.
Access to the raia production network (e.g., Google Cloud) must be secure.
No confidential information shall be sent from to an individual or entity outside of raia using personal email accounts.
Personnel must use the production network and internet only for lawful purposes.
Encryption
raia users who are in travel status and use laptops to access the production network or company data should reasonably ensure such transmissions are encrypted and only access the network through authorized means. During travel, access to the internet should only be made via secure wireless networks.
Explicit Content
Users using raia devices who discover they have connected with a web site that contains sexually explicit, racist, violent, or other potentially offensive material must immediately leave the site and report such use to r@raiaai.com.
Prohibited Uses
You agree not to use personal email accounts for, but not limited to:
- Dissemination of confidential information.
- Attempting to gain access to another Internet account, without permission.
- Sending confidential information over the Internet without proper encryption.
You agree not to use network and internet access to:
- Violate any applicable federal, state, local, or international law or regulation (including, without limitation, any laws regarding the export of data or software to and from the US or other countries).
- Access data, a server or an account for any purpose other than conducting raia business, even if you have authorized access.
- Make statements about warranty, expressly or implied, unless it is a part of normal job duties.
- Make fraudulent offers of products, items, or services originating from any raia account.
- For the purpose of exploiting, harming, or attempting to exploit or harm, minors in any way by exposing them to inappropriate content, asking for personally identifiable information, or otherwise.
- Send, knowingly receive, upload, download, use, or re-use any material which violates the rights of any individual or entity established in any jurisdiction.
- Transmit, or procure the sending of, any advertising or promotional material, including any "junk mail," "chain letter," "spam," or any other similar solicitation.
- Impersonate or attempt to impersonate raia, an employee, contractor, another user, or any other person or entity (including, without limitation, by using e-mail addresses or screen names associated with any of the foregoing).
- Engage in any other conduct that restricts or inhibits anyone's use of the network, or which, as determined by us, may harm raia or users of the network or expose them to liability.
- Disable, overburden, damage, or impair the network or interfere with any other party's use of the network, including their ability to engage in real time activities through the network.
- Use any robot, spider, or other automatic device, process, or means to access the network for any purpose, including monitoring or copying any network traffic or resources available on the network.
- Use any manual process to monitor or copy any network traffic or resources available on the network or for any other unauthorized purpose without raia's prior written consent.
- Use any device, software, or routine that interferes with the proper working of the network.
- Introduce any viruses, honeypots, trojan horses, worms, logic bombs, or other software or material which is malicious or technologically harmful.
- Attempt to gain unauthorized access to, interfere with, damage, or disrupt any parts of the network or any server, computer, database, or other resource or element connected to the network.
- Violate, attempt to violate, or knowingly facilitate the violation of the security or integrity of the network.
- Use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications.
Content Standards
You agree not to send, knowingly receive, upload, download, use, or re-use any material which:
- Contains any material that is defamatory, obscene, indecent, abusive, offensive, harassing, violent, hateful, inflammatory, or otherwise objectionable.
- Promotes sexually explicit or pornographic material, violence, or discrimination based on race, sex, religion, nationality, disability, sexual orientation, or age.
- Infringes any patent, trademark, trade secret, copyright, or other intellectual property or other rights of any other person.
- Violates the legal rights (including the rights of publicity and privacy) of others or contains any material that could give rise to any civil or criminal liability under applicable laws or regulations.
- Is likely to deceive any person.
- Promotes any illegal activity, or advocates, promotes, or assists any unlawful act.
- Causes annoyance, inconvenience, or needless anxiety or is likely to upset, embarrass, alarm any other person.
- Impersonates any person, or misrepresents your identity or affiliation with any person or organization.
- Gives the impression that material emanates from or is endorsed by raia or any other person or entity, if this is not the case.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Access Control and Termination Policy
Purpose and Scope
This Access Control and Termination Policy defines requirements for access and removal of access to raia data, systems, facilities, and networks. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets or approved devices utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept, and follow all raia policies and plans.
Access Control Requirements
Principle of Least Privilege
raia adheres to the principle of least privilege, specifying that users of raia systems will be given minimum access to data and systems based on job function, business requirements, or need-to-know for that specific user. Access to systems should be provisioned via a deny-all methodology - users should only gain access to a system upon receiving formal independent approval.
Administrative access to production servers and databases is restricted based on the principle of least privilege for personnel who have a job function and business need for such access. Access to systems and applications must be controlled by a secure log-on process to prove the identity of the user.
Unique Accounts
Users of raia systems and applications will be provided with unique credentials (IDs, keys, etc.) that can be used to trace activities to the individual responsible for that account. Shared user accounts shall only be utilized in circumstances where there is a clear business benefit and when user functions do not need to be traced. Shared account password should only be stored in a raia approved password manager.
Password Security
Unique accounts and passwords are required for all users. Passwords must be kept confidential and not shared with multiple users. Where possible, all user and system account passwords must be a minimum of eight characters and complex. All accounts must use unique passwords not used elsewhere.
Rotation Requirements
If an account is suspected to be compromised, the password should be reset and the security team should be immediately notified.
Storing Passwords
Passwords must only be stored using a raia approved password manager. raia does not hard code passwords or embed credentials in static code.
Multi-Factor Authentication
When available, multi-factor authentication should be used. Multi-factor authentication must be used for access to company email, version control tool and cloud infrastructure.
Onboarding Procedures
In order to onboard new personnel, the following steps should be taken and documented:
- Any raia devices provided to the new hire must be inventoried in accordance with raia policy
- A new hire email or ticket must be sent to the appropriate team to inform them of new personnel
- IT/Engineering and the new personnel’s manager must document a checklist of accounts and permission levels needed for that hire
- The applicable team must set up each user with the appropriate access, both logical and physical
- All of the onboarding processes must be appropriately documented via ticketing or other document management tools
Offboarding Procedures
In order to offboard an employee or contractor, the following steps must be taken:
- An offboarding email or ticket must be sent to IT/Engineering when personnel has been terminated or resigned informing IT/Engineering of the team members’ last day
- IT/Engineering must review and perform action against the appropriate revocation checklist to revoke access to raia systems, applications, and physical access points (as applicable) within 24 hours of the last day with the company or sooner if necessary
- Any raia devices provided must be collected and accounted for in accordance with raia policy
- All of the offboarding processes must be appropriately documented via raia ticketing or other document management tools
Changes to Access
Requests for changes to access level(s), such as in the cases of a change in job duties or an emergency requiring elevated permissions, must be documented and approved by the appropriate manager.
A documented request must be sent to the appropriate department when an employee or contractor role changes to evaluate whether access privileges should be changed. When accounts are no longer required, user access rights must be reviewed and reallocated as necessary prior to changes being made.
Such changes must be tracked using the raia ticketing or other document management tools.
Quarterly Access Reviews
A team manager must review, audit, and document user accounts and associated privileges of at least high-risk and critical systems at least quarterly to ensure that access is restricted appropriately.
Exceptions
raia business needs, local situations, laws, and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Business Continuity and Disaster Recovery Plan
Purpose and Scope
This Business Continuity and Disaster Recovery Plan guides raia in the event of a significant business disaster or other disruption to normal service. raia must respond to business disasters and disruption by safeguarding employees’ lives and company assets, making a financial and operational assessment, securing data, and quickly recovering operations.
This plan applies to all raia assets utilized by employees and contractors acting on behalf of raia or accessing its applications, infrastructure, systems, or data. All employees and contractors are required to read, accept, and follow all raia policies and plans.
Scope for Mission Critical Services
Mission critical services and systems are those required for the functioning of the raia product(s). Mission Critical services and systems include critical production systems required for immediate recovery, services affecting the engineering team’s ability to support production operations and product development, and the ability to support raia customers.
All essential data is typically stored remotely using commercial cloud providers with proper backup and redundancy processes in place. This approach is subject to change and designed to minimize any disruption from physical incidents or disasters.
System Outages
Planned Outage
From time to time, raia may distribute a service update to all affected users prior to planned downtime.
Unplanned Outage
All unplanned outages should be treated as an incident; r@raiaai.com and the executive team should be immediately emailed and notified of any unplanned outage.
Expectations
Alternate Physical Location(s) of Employees
In the event of an internal disaster that affects a raia office location, all team members will be moved from such affected offices to each member’s respective home or an alternate location to work remotely.
Reliance on Third-Party Services
raia utilizes and relies on mission critical third-party cloud services. In the event of a significant business disaster, raia will quickly work to establish alternative arrangements if a mission critical vendor can no longer provide the needed services or goods.
Mission critical third-party vendors include:
- Google Cloud
- Google Workspace
- GitHub
- OpenAI
- Stripe
- n8n
This plan depends on the likelihood that:
- Remote work can continue to take place in the event of a disaster; and
- Mission critical vendor services, and essential raia services, systems, and data can still be made available or alternative solutions can be implemented (including backups and services provided by such third-party vendors)
Priorities
In the event of a disaster affecting raia essential systems or its team members, raia Management will oversee and respond in accordance with this Plan and will initiate specific actions for recovery.
The priorities during a business disaster are to:
- Secure the safety of team members and visitors;
- Mitigate threats or limit the damage that threats can cause to raia, its team, and its customers; and
- Ensure that essential business functions can continue or determine what is required to restart essential business functions
Backup and Retention
All vital data that would be affected by disruption are maintained and controlled by the data’s applicable teams.
In the event of a facility disruption, critical records located in such a facility may be destroyed or inaccessible. The number of critical records, which would have to be reconstructed, will depend on when the last transfer of critical records to the cloud storage location occurred.
Backup Requirements
- Database backups must be performed daily
- Backups must be retained for at least 30 days
- The maximum allowable retention period for a database backup should be determined based on regulatory and contractual requirements
- Backups are periodically tested to ensure that backups are sufficient and reliable in accordance with this plan
- Backup systems and media protect the availability of stored data
Alternate Communication
The organization may communicate using telephone, video conferencing tools, messaging tools, email, physical mail, and in person.
In the event of a significant business disaster, an assessment will be conducted to determine which means of communication are still available. These means of communication will then be utilized to communicate with personnel, customers, partners and other third-parties.
Testing
Testing the plan is critical to ensuring the plan is effective and practical. Any gaps in the plan that are discovered during the testing phase will be addressed by raia Management and any designee. All tests must be thoroughly documented.
Testing of this plan may be performed using the following methods noted in the subsections below.
Walkthroughs
Team members must walk through the steps documented in this plan to confirm effectiveness, identify gaps, bottlenecks or other weaknesses. This walkthrough provides the opportunity to review the plan with all relevant stakeholders and familiarize them with procedures, equipment, offsite facilities, and recovery efforts in preparation of a business disaster or disruption.
Table Top Exercises
Hardware, software, personnel, communications, procedures, supplies and forms, documentation, transportation, utilities, and alternate site processing should be thoroughly tested in a simulation test.
Personnel involved with business continuity must utilize validated checklists to provide a reasonable level of assurance for many disaster scenarios. These personnel must analyze the output of the previous tests carefully before the proposed simulation to ensure the lessons learned during the previous phases of the cycle have been applied.
Business Continuity and Disaster Recovery Stages
This Plan divides recovery into three stages: Disaster, Response, and Recovery.
Declaring a disaster is the responsibility of senior management. Since it is almost impossible to predict when and how a disaster might occur, raia and its team members must be prepared to monitor and signal a disaster to management from:
- First hand observation
- Security applications
- Network monitoring and logging tools
- Environmental and security alarms
- Team members
- Customers
- Partners
- Vendors
- Media
Disaster Stage
If a disaster has been declared, this Plan and any related responses would go into effect.
The disaster stage may include the following processes:
- Senior management declares the disaster, and
- Notifies management and appropriate team members to create the appropriate Disaster Recovery Team (DRT) consisting of raia Management (lead), Thomas Hall, and Lee Dickson,
- DRT initiates internal and external communication lines, and communicates to the following parties as appropriate:
- General Counsel
- Authorities
- Personnel
- Customers
- Vendors, third-parties, and other applicable stakeholders
- DRT determines appropriate emergency response measures
Response Stage
In this phase, the team determines what team members, facilities and customer deployments are affected by the disaster scenario and in what way they are affected by performing an impact assessment.
This stage continues until an alternate facility location and/or essential business and production functions are established and services restored. If non-essential functions are affected, essential functions may be prioritized during a disaster event.
The response stage may include the following processes:
- Execution of a business impact assessment,
- Relocation to an alternative facility or establish work from home requirements,
- Verification and/or backing up of affected data and systems, and
- Restoration of essential raia services
Recovery Stage
Recovery begins with the activities necessary to return to business as usual including re-establishing the primary facility. For engineering, this stage begins with the restoration of raia services in an available commercial cloud provider’s region. Recovery time objectives (RTOs) and recovery point objectives (RPOs) are to be defined when relevant for applicable systems.
- Recovery time objective(s) (RTO): 4 hours
- Recovery point objective(s) (RPO): 1 hour
Key Learning Stage
As soon as possible, raia senior management must meet with the DRT and other stakeholders for a post-mortem review to better understand the disaster event that took place and how it and others may be prevented in the future.
The retrospective must be documented and key learnings from the retrospective should be presented to all appropriate team members in a timely manner.
Lessons learned during the disaster must be captured within the post-mortem review and incorporated as updates into existing documentation.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
This Business Continuity and Disaster Recovery Plan is reviewed and tested at least annually. Ensuring that the plan reflects ongoing changes to resources is crucial. This task includes updating the plan, testing the updates with walkthroughs, tabletop exercises, and training necessary personnel. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually.
This development, maintenance, and testing of this plan are approved by raia Management.
This plan was last updated on May 7, 2026.
raia
Purpose and Scope
This Change Management Policy defines how changes to applications, systems, services, and infrastructure are planned and implemented. The goal of change management is to increase awareness and understanding of proposed changes across raia and ensure that all changes are made in a thoughtful way that minimize negative impact to services and customers.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets and personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans.
Change Management
All code change requests and critical infrastructure or network-related change requests must be documented end-to-end via raia's change management and ticketing tools (e.g., Confluence, GitHub).
Change management should be conducted according to the following procedure:
(1) Product Roadmap
The raia product management team evaluates which change requests and features will be implemented based on their alignment with the business plan and the overall level of effort required. All change requests should be prioritized in terms of benefits, urgency, effort required, security impacts, and other potential impacts on the organization’s operations.
A ticket should be created to track a change request at the onset. If the change is part of an existing ticket the original ticket may be used and modified appropriately.
(2) Planning and Evaluation
Planning and evaluation must include design, scheduling, and implementation of a communications plan, testing plan, and roll-back plan. During planning, wire-frames, mockups, and functional requirements may be created and reviewed among the applicable team members. The team may set priority levels of the service and may determine any risk that the proposed change introduces to the system. It is during this phase that the scope and impact of the change will be determined.
(3) Build, Test, and Document
During building, raia sprints may be defined and the overall software design and development occurs.
UI/UX and other optimizations should be performed during this phase to enhance the performance and security of the change across all platforms.
The changes must be tested in a non-production environment before release to production. Test setups and scenarios are built for operational, performance, and security testing. Test scripts and suites should be developed, used, and updated as changes occur.
Documentation must be updated during this phase, such as release notes, help articles, and blog posts. Existing documentation is updated to ensure that team members and customers have the most up-to-date and accurate information related to the changes performed. Customer-facing documentation should be provided to raia customers as applicable.
(4) Code Review
raia uses code reviews to maintain the quality of raia code and products. Code reviewers should look at:
- Design: Is the code well-designed and appropriate for your system?
- Functionality: Does the code behave as intended by the plan? Is the way the code behaves good for its users?
- Complexity: Could the code be made simpler? Would another developer be able to easily understand and use this code when they come across it in the future?
- Tests: Does the code have correct and well-designed automated tests?
- Security: Are there any security risks in the code as identified by the latest OWASP Top 10?
- Naming: Are there clear names for variables, classes, methods, etc.?
- Comments: Are the comments clear and useful?
- Style: Does the code follow raia style guides?
- Documentation: Was the relevant documentation updated or created?
Secure Coding
Secure coding practices are incorporated into the development lifecycle and security architecture of raia. Engineers at raia are responsible for defining security requirements initially and throughout all phases of the software development life cycle and then evaluating for compliance with those requirements.
(5) Approval and Implementation
Once the new release is ready for deployment and the appropriate documentation is in place, the new release must be approved and reviewed by the appropriate product owner prior to being pushed to the production environment.
The ability to push changes to production at raia must be restricted to a limited set of authorized team members, and the engineer responsible for coding the change should not also be responsible for pushing the change to production, unless there is prior approval of the exception by management.
(6) Communication
Implemented changes should be communicated to all applicable team members and externally as appropriate.
(7) Post-Change Review
raia continuously measures the success of new releases and identifies areas that can be enhanced further in the future.
The appropriate team must conduct a post-implementation review to determine how the change is impacting raia and raia's customers, either positively or negatively. Discuss and document any lessons learned with product management and other appropriate team members.
raia must utilize version control tools (e.g., GitHub) that allow for efficient rollbacks of commits from production if any issues arise during the post-change review.
Hotfixes / Critical Issues / Emergencies
The following are potential emergencies that may require a hotfix:
- A customer is completely out of service
- There is severe degradation of service needing immediate action
- A system/application/component is inoperable and the failure causes a significant negative impact
- A response to a natural disaster
- A response to an emergency business need
- A critical vulnerability or security issue is identified
If a hotfix is required, the applicable manager should be immediately notified.
The notification should include at a minimum the following information:
- Will the change cause an interruption in service?
- What additional customers will be affected (in the event a change is needed to fix an outage) and who needs to be notified?
- What is the possible workaround until the problem is resolved?
- What is the approximate length of the outage?
- Notification of resolution
- Submission of a ticket to accurately describe the outage
Emergencies after normal business hours, on the weekend, or on holidays, must follow an appropriate communication and resolution process. A ticket must be generated and team members may need to notify affected customers, as determined by management. Emergency changes must be revisited to ensure no additional security issues were introduced into the product, service, or supporting infrastructure. A completed ticket should be submitted through the regular reporting process promptly following when the change was made.
Management must review all emergency submissions to ensure the change met the criteria for an “emergency change” and to prevent the process from becoming normal practice to circumvent the Change Management Policy. Any questions will be directed to the individual(s) who approved the change.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
This Code of Conduct outlines raia's expectations measured against the highest possible standards of ethical business conduct. Committing to the highest standards helps raia hire great people, build great products, and attract loyal customers.
From time to time, raia may update this Code of Conduct. This policy is guided by requirements specific to raia including applicable laws and regulations.
We expect all raia personnel to review, understand, and abide by this Code of Conduct in all matters related to raia.
Respect in the Workplace
All personnel must respect their colleagues. raia will not allow any kind of discriminatory behavior, harassment, or victimization.
raia prohibits retaliation against any personnel who report or participate in an investigation of a possible violation of raia's Code of Conduct, policies, or the law. If you believe you are being retaliated against, please contact raia Management, another senior manager, or anonymously at r@raiaai.com.
Personnel must use company assets as outline in the Acceptable Use Policy. This includes safe handling of trademarks, copyright, and other property (information, reports, etc.).
Safe Workplace
raia is committed to a violence-free work environment, and we will not tolerate any level of violence or the threat of violence in the workplace. Under no circumstances should anyone bring any type of weapon to work including guns, explosives, or knives. If you become aware of a violation of this policy, you should report it to a member of management immediately. In the case of potential physical violence, contact the authorities immediately.
Workplace Visitors
Workplace safety is very important to raia. As raia visitors access workplace premises, raia should ensure that visitors are not a threat to the workplace and are not exposed to danger.
Equal Opportunity Employment
raia is an equal opportunity employer. raia thrives on diversity and are committed to creating an inclusive environment for all personnel.
Professionalism
All personnel must show integrity and professionalism in the workplace.
Job Duties and Authority
All personnel should fulfill their job duties with integrity and respect toward customers, stakeholders and the community. Supervisors and managers must not abuse their authority.
We encourage mentorship throughout raia.
Communication and Collaboration
Personnel should be responsive and open for communication with their colleagues, supervisors, and team members. Personnel should be friendly and collaborative and not disrupt the workplace or hinder their colleagues' work.
Benefits
raia expects employees to not abuse their employment benefits. Please reach out to Human Resources for questions pertaining to company benefits.
Compliance with Law
Personnel must comply with all applicable laws including environmental, safety and fair dealing laws. raia expects everyone to be ethical and responsible during raia business dealings.
Conflict of Interest
Conflicts of interest occur when an employee, contractor, or job applicant's personal interests may not align with company needs or interests. We expect you to avoid any personal, financial, or other interests that might hinder your capability or willingness to perform your job duties. If you believe that a conflict may occur, please contact your manager immediately.
Types of conflicts of interest may include:
- Personal investments
- Outside employment, advisory roles, board seats, and starting your own business
- Business opportunities found through work
- Inventions
- Accepting gifts, entertainment, and other business courtesies
Internet and Social Media
Personnel should never share any intellectual property or the status of any of their assignments on social media.
When representing the company, personnel should always be respectful and avoid speaking in specifics about their work. Personnel should never post discriminatory, offensive, or other illegal language on social media.
Exceptions
raia business needs, local situations, laws, and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee's or contractor's course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Purpose and Scope
This Configuration and Asset Management Policy provides procedures supporting effective organizational asset management, specifically focused on electronic devices within the organization and baseline configurations for raia assets and systems.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans.
Configuration Standards
Production systems handling confidential data must have documented baseline configurations, when available. raia management is responsible for following documented standard configurations for all applicable assets including third-party cloud products and employee devices. Configuration standards should be available for reference by applicable personnel.
raia must continuously harden its systems via Secureframe compliance and security checks as well as Center for Internet Security (CIS) benchmarks and best practices. The compliance checks monitor system security parameters and safeguards.
raia must regularly patch and keep all applicable systems up to date.
All vendor supplied default configurations, including but not limited to passwords, user accounts, and administrative accounts, should be changed before any systems or devices are implemented.
Each applicable asset and system in the raia environment should be hardened to the minimum standards defined by raia management.
Hardening standards should be in line with industry standards and provide sufficient logical and physical security for the asset(s) being configured.
Minimum Device Configuration Settings
raia devices should be configured to these settings where possible:
- Encryption: User endpoint storage is encrypted at rest (e.g. FileVault for MacOS or Bitlocker for Windows)
- Security Updates: OS security updates are enforced and monitored
- Malware Protection: Malware protection is enabled (e.g XProtect for MacOS, Defender for Windows, or ClamAV for Linux)
- Screensaver / Lockscreen: Screensavers / lockscreens are configured to activate after a maximum of 15 minutes
- Logging: Logs are captured and stored to assist with security investigations
- Password Policy: Required passwords must align with raia's Access Control and Termination Policy
- Firewall: Local firewall is enabled to provide layered host protection unless it interferes with development activities
- Remote Wipe (Optional): In the event of employee departure or theft, the mobile devices can be remotely wiped
Non-Standard Configuration
If an asset must use a non-standardized configuration, approval of the use must be provided by raia management and such approval and request must be documented.
Asset Management
raia inventories and tracks all assets that are used to process, store, transmit, or otherwise impact the confidentiality, integrity, or availability of sensitive information. The asset inventory will include all systems connected to the network and network devices themselves. Examples of items to be inventoried are servers, datastores, network devices, applications, and workstations.
Lost Asset
If an asset is known to be lost or stolen, please report it immediately to r@raiaai.com.
Acquisition of New Assets
Business considerations must be reviewed, documented, and addressed prior to the acquisition of any new assets. raia management must approve any new assets that may be used to access raia data, systems, network, or applications. Reference the Data Classification Policy for more information.
Data as an Asset
Sensitive data is also considered an asset and should be tracked accordingly. Sensitive data must be stored in accordance with all security policies and the location of all covered data regardless of classification or encryption status must be maintained.
Asset Management Procedures
raia must maintain an inventory of servers, desktops, laptops, and other devices used to store, create, modify, delete, or transmit confidential information.
All assets should be mapped to the device’s serial number or another identifier.
Any asset no longer in use or deemed no longer usable will be removed from the inventory.
raia must perform periodic asset management system checks for various classes of asset records.
Any raia devices issued to personnel must be returned upon termination or resignation.
Asset Inventory Audit
raia Management or a designee will be held accountable for the accuracy of the inventory and must perform a documented review of the asset list at least annually.
Physical Media Transfer
Any media or device containing sensitive data must be shipped by a tracked carrier with a recipient signature required. For encrypted data, the encryption key should only be released after the package has arrived and been signed for. Media containing data will be protected against unauthorized access, misuse or corruption during transportation.
Legal advice should be sought to ensure compliance before media containing encrypted information or cryptographic controls are moved across jurisdictional borders.
Asset Disposal
When disposing of any asset, sensitive data must be removed prior to disposal. Any physical media storing confidential or personally identifiable information that is not being repurposed must be destroyed prior to disposal. Sanitization should occur in accordance with the NIST Guidelines for Media Sanitization (NIST S.P. 800-88 Rev. 1).
raia's third-party providers are responsible for physical protections and disposal of all assets under their control such as databases and servers.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
This Data Classification Policy provides the basis for protecting the confidentiality of data at raia by establishing a data classification system. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia data assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans.
Classification Management
All raia data should be classified into one of the following four classifications:
- Restricted Data,
- Confidential Data,
- Internal Data, and
- Public Data.
All data that is not explicitly classified should be treated as confidential data and a classification should be determined and documented.
The examples below are not exhaustive. Data owners and senior management are responsible for assigning the types of ways certain data can be used as well as assigning the appropriate classification to raia data.
If you are unable to determine the appropriate data owner or a classification for the data or believe certain data should be reclassified, please contact r@raiaai.com.
Changes to the classification of data must be approved by senior management.
Classification Levels
Public Data
Public data is information that may be disclosed to any person regardless of their affiliation with raia. The Public classification is not limited to data that is of public interest or intended to be distributed to the public; the classification applies to data that does not require any level of protection from disclosure. While it may be necessary to protect original (source) documents from unauthorized modification, Public data may be shared with a broad audience both within and outside raia and no steps need be taken to prevent its distribution. Public data can be retained for an indefinite period of time.
Examples of Public data include:
- published press releases;
- published documentation,
- published blog posts,
- anything on the raia public website, and
- anything on raia social media profiles
Internal Data
Internal data is information that is potentially sensitive and is not intended to be shared with the public. Internal data should be classified as such when the unauthorized disclosure, alteration, or destruction of that data would result in moderate risk to raia, its customers, or its partners. Internal data generally should not be disclosed outside of raia without the permission of the data owner. It is the responsibility of the data owner to designate information as Internal where appropriate. If you have questions about whether information is Internal or how to treat Internal data, you should talk to your manager or send an email to r@raiaai.com.
Examples of Internal data include:
- unpublished raia memos,
- unpublished marketing materials,
- non-public raia customer and partner names, and
- procedural documentation that should remain private
Confidential Data
Confidential data is information that, if made available to unauthorized parties, may adversely affect individuals or raia. This classification also includes data that raia may be required to keep confidential, either by law or under a confidentiality agreement with a third party, such as a vendor. This information should be protected against unauthorized disclosure or modification. Confidential data should be used only when necessary for business purposes and should be protected both when it is in use and when it is being stored or transported. Confidential data should be retained for only as long as it is needed to conduct internal/external business operations. Customer deletion requests and contractual deletion obligations should be the main source of authority for storing/deleting Confidential data.
Any unauthorized disclosure or loss of Confidential data must be reported to r@raiaai.com.
Examples of Confidential data include:
- individual employment information, including salary, benefits and performance evaluations for current, former, and prospective employees,
- legal documents,
- customer data,
- contractual agreements,
- compliance reports such as SOC 2,
- data that is subject to an NDA or other confidentiality clause, and
- information shared by partners or investors
Restricted Data
Restricted data includes any information that raia has a legal or regulatory obligation to safeguard in the most stringent manner. Data should be classified as Restricted when the unauthorized disclosure, alteration or destruction of that data could cause a significant level of risk to raia, its customers, or its partners. The highest level of security controls should be applied to Restricted data.
Examples of Restricted data include:
- raia codebase,
- intellectual property,
- passwords, private keys and other credentials,
- bank information,
- tax ids,
- information related to pending litigation or investigations,
- data required to be protected by regulatory obligations, and
- additional employment information such as background checks, health and medical information, social security numbers
Restricted data should be used only when no alternative exists and must be carefully protected. Regulatory data retention requirements should be the main source of authority for storing/deleting restricted data, as applicable, unless stricter organizational requirements have been enacted. Any unauthorized disclosure, unauthorized modification, or loss of Restricted data must be immediately reported to your manager and r@raiaai.com.
Data Handling and Labeling
All personnel accessing classified information must follow the rules listed above. Each incident related to handling classified information must be reported in accordance with the Security Incident Response Plan.
All types and forms (e.g. digital, physical) of data should be clearly labeled, denoting respective classification tiers. As mentioned above, all data not explicitly classified must be treated as if it were confidential data. Classification tiers with labels are listed below:
- Public Data -> "FOR PUBLIC USE"
- Internal Data -> "CLASSIFICATION: INTERNAL"
- Confidential Data -> "CLASSIFICATION: CONFIDENTIAL"
- Restricted Data -> "CLASSIFICATION: RESTRICTED"
All physical (e.g. paper, posters, etc.) and digital (e.g. Word/Google Docs, Excel/Google Sheets, PowerPoint/Google Slides) media should have a footnote clearly stating the proper classification level at the bottom of each page/sheet/slide.
Data Storage
Personnel should be mindful of where to store data based on the degree of classification. Where possible, personnel should observe the principle of least privilege, or sharing only what absolutely needs to be known. For example, there is no need to share restricted data to persons who do not have the need to know. Personnel should be especially mindful when sharing data to external users outside of the company.
Data Deletion
The method for secure erasure and destruction of media is prescribed in the Configuration and Asset Management Policy and Data Retention and Disposal Policy.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
This Data Retention and Disposal Policy addresses how a customer's data is retained and disposed of and to ensure this is carried out in a consistent manner. From time to time, raia may update this policy. This policy is guided by security requirements specific to raia including compliance with applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems, or data. All personnel are required to read, accept, and follow all raia policies and plans.
Data Retention
The time period for which raia must retain customer data depends on the purpose for which it is used. raia must retain customer data for as long as an account is active or in accordance with the agreement(s) between raia and the customer, unless raia is required by law or regulation to dispose of data earlier or retain data longer.
Data Disposal
raia must dispose of customer data within 30 days of a request by a current or former customer or in accordance with the Customer's agreement(s) with raia. raia may retain and use data necessary for the contract such as proof of contract in order to comply with its legal obligations, resolve disputes, and enforce agreements. raia hosting and service providers (such as Google Cloud) are responsible for ensuring the removal of data from disks allocated to raia use before they are repurposed and the destruction of decommissioned hardware.
Only a limited number of raia employees should have access to delete customer data.
Upon employee or contractor termination, company-owned devices will be collected and sanitized prior to device re-issuance in accordance with NIST Guidelines for Media Sanitization (NIST S.P. 800-88 Rev. 1).
GDPR Right to Erasure and Data Subject Rights
In accordance with Article 17 of the General Data Protection Regulation (GDPR), individuals located in the EU/EEA have the right to request erasure of their personal data ("right to be forgotten"). raia must erase personal data without undue delay where:
- The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
- The data subject withdraws consent and there is no other legal ground for the processing;
- The data subject objects to the processing and there are no overriding legitimate grounds;
- The personal data has been unlawfully processed;
- The personal data must be erased for compliance with a legal obligation; or
- The personal data was collected in relation to the offer of information society services to a child.
Exceptions to Erasure:
The right to erasure does not apply to the extent that processing is necessary for:
- Exercising the right of freedom of expression and information;
- Compliance with a legal obligation requiring processing;
- Reasons of public interest in the area of public health;
- Archiving purposes in the public interest, scientific or historical research, or statistical purposes; or
- The establishment, exercise, or defense of legal claims.
Response Timeline:
raia must respond to erasure requests without undue delay and in any event within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. raia must inform the data subject of any such extension within one month of receipt of the request.
Notification to Third Parties:
Where raia has made the personal data public or has disclosed it to third-party processors, raia must take reasonable steps to inform those processors that the data subject has requested erasure of any links to, or copies of, that personal data.
Data Portability (GDPR Article 20)
Where processing is based on consent or a contract, and is carried out by automated means, data subjects in the EU/EEA have the right to receive their personal data in a structured, commonly used, and machine-readable format. Where technically feasible, raia will transmit the data directly to another controller at the data subject's request.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Purpose and Scope
This Encryption and Key Management Policy provides guidance on the types of devices and media that need to be encrypted, when encryption must be used, the minimum standards of the software used for encryption, and the requirements for generating and managing keys at raia. Following documented policy will limit mistakes in selecting keys, implementing the encryption/decryption process, and managing keys and other secrets which are common causes of data exposure.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems, or data. All personnel are required to read, accept, and follow all raia policies and plans.
Cryptographic Key Requirements
raia must use industry-approved strong algorithms for encryption processes for data-in-transit and data-at-rest.
Strong Standards
Transport Layer Security
raia uses strong cryptography and security protocols (TLS 1.2+ or a minimally equivalent protocol) to safeguard sensitive data during transmission over open, public networks. raia protects the integrity and confidentiality of data passing over public networks from fraudulent activity, contract dispute, and unauthorized disclosure and modification.
raia prohibits the transmission of unprotected sensitive data using insecure end-user messaging technologies.
Databases at Rest
raia requires that the encryption of data-at-rest should only include strong encryption methods (AES-256 or a minimally equivalent protocol).
Reference the following for guidance on encryption algorithms: NIST Security Requirements for Cryptographic Modules (FIPS 140-3) and NIST CMVP Approved Security Functions (S.P. 800-140C).
Key Management
Keys must be protected to prevent unauthorized disclosure and subsequent fraudulent use.
- Users handling private keys must physically and logically secure them.
- Do not share keys with anyone else.
- Never re-use keys to encrypt other information.
Generating Keys
To generate a key, users must use an industry-standard random key generating mechanism. Reference OWASP Key Management Cheat Sheet for guidance.
Keys should not be based on common words or phrases.
Key Rotation
Encryption keys should be changed (or rotated) based on a number of different criteria:
- If the key is or may be compromised. For example, an ex-employee may have had access to a key.
- After a specified period of time has elapsed (known as the cryptoperiod). See Section 5.3 of NIST Recommendation for Key Management for guidance.
- After the key has been used to encrypt a specific amount of data.
- If there is a significant change to the security provided by the algorithm (such as a new attack being announced).
Key Storage
When available, the secure storage mechanisms provided by the operating system, framework or cloud service provider should be used. The key management system must ensure that all encryption keys are secured and there is limited access to raia personnel.
This may include:
- A physical Hardware Security Module (HSM)
- A virtual HSM
- Key vaults such as Google Cloud Key Management Service (KMS)
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia Management or a designee is responsible for ensuring compliance across raia with respect to this policy with the use of a variety of monitoring tools.
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is maintained by raia Management.
This document was last updated on May 7, 2026.
raia
Purpose and Scope
This Information Security Policy addresses the information security policy topics and requirements which maintain the security, confidentiality, integrity, and availability of raia applications, systems, infrastructure, and data. The topics and requirements called out in this policy should be continuously improved upon to maintain a secure information security posture.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including compliance with applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans upon starting and at least annually.
Information Security Communication
Please contact r@raiaai.com if you have any questions about the raia information security program.
People Security
Background Check
All raia personnel are required to complete a background check. An authorized member of raia must review each background check in accordance with local laws.
Confidentiality
Prior to accessing sensitive information, personnel are required to sign an industry-standard confidentiality agreement protecting raia confidential information.
Security Awareness Training
raia has a security awareness training program in place to promote the understanding of security policies and procedures. All personnel are required to undergo training following initial employment and annually thereafter. Completion of the training program is logged by raia in Secureframe.
Secure Coding
raia promotes the understanding of secure coding to its engineers in order to improve the security and robustness of raia products.
Physical Security
Clear Desk
raia personnel are required to ensure that all sensitive information in hardcopy or electronic form is secure in their work area when it is unattended. This requirement extends to both remote and in-office work.
raia personnel must remove hardcopies of sensitive information from desks and lock the information in a drawer when desks are unoccupied and at the end of the work day. Keys used to access sensitive information must not be left at an unattended desk.
Clear Screen
raia employees and contractors must be aware of their surroundings at all times and ensure that no unauthorized individuals have access to see or hear sensitive information. All mobile and desktop devices must be locked when unoccupied. Session time-outs and lockouts are enforced through technical controls for all systems containing covered information.
All devices containing sensitive information, including mobile devices, shall be configured to automatically lock after a period of inactivity (e.g. screen saver).
Remote Work
Any raia issued devices used to access company applications, systems, infrastructure, or data must be used only by the authorized employee or contractor of such device.
Employees or contractors accessing the raia network or other cloud-based networks or tools are required to use HTTPS/TLS 1.2+ at a minimum to protect data-in-transit.
If you are in a public space, ensure your sight lines are blocked and do not have customer conversations or other confidential conversations. If someone is close to you, assume they can see and hear everything. Connecting directly to a public wireless network that doesn't employ, at minimum, WPA-2 or an equivalent wireless protocol is prohibited.
While working at home, employees and applicable contractors should be mindful when visitors (e.g. maintenance personnel) are at their residences, as visitors could become privy to sensitive information left up on computer screens.
System Access Security
raia adheres to the principle of least privilege, specifying that team members will be given access to only the information and resources necessary to perform their job functions as determined by management or a designee. Requests for escalation of privileges or changes to privileges and access permissions are documented and require approval by an authorized manager. System access is revoked immediately upon termination or resignation.
Account Audits
Audits of access and privileges to sensitive raia applications, infrastructure, systems, and data are performed regularly and reviewed by authorized personnel.
Password Security
Unique accounts and passwords are required for all users. Passwords must be kept confidential and not shared with anyone. Where possible, all user and system accounts must invoke password complexity requirements specified in the Access Control and Termination Policy. All accounts must use unique passwords not shared with any other accounts.
Rotation Requirements
If a password is suspected to be compromised, the password should be rotated immediately and the security team should be immediately notified.
Storing Passwords
Passwords must only be stored using a raia approved password manager. raia does not hard code passwords or embed credentials in static code.
Asset Security
raia maintains a Configuration and Asset Management Policy designed to track and set configuration standards to protect raia devices, networks, systems, and data. In compliance with such policy, raia may provide team members laptops or other devices to perform their job duties effectively.
Data Management
raia stores and disposes of sensitive data, in a manner that; reasonably safeguards the confidentiality of the data; protects against the unauthorized use or disclosure of the data; and renders the data secure or appropriately destroyed. Data entered into raia applications must be validated where possible to ensure quality of information processed and to mitigate the impacts of web-based attacks on the systems.
Data Classification
raia defines the handling and classification of data in the Data Classification Policy.
Data Retention and Disposal Policy
The time periods for which raia must retain customer data depends on the purpose for which it is used. raia retains customer data as long as an account is active, as needed to provide services to the customer, or in accordance with the agreement(s) between raia and the customer. An exemption to this policy would include if raia is required by law to dispose of data earlier or keep data longer. raia may retain and use customer data to comply with its legal obligations, resolve disputes, and enforce agreements.
Except as otherwise set forth in the raia policies, raia also disposes of customer data when requested by customers.
raia maintains a sanitization process that is designed to prevent sensitive data from being exposed to unauthorized individuals. raia hosting and service providers are responsible for ensuring the removal of data from disks allocated to raia use before they are repurposed or destroyed.
Change and Development Management
To protect against unauthorized changes and the introduction of malicious code, raia maintains a Change Management Policy with change management procedures that address the types of changes, required documentation, required review and/or approvals, and emergency changes.
Changes to raia production infrastructure, systems, and applications must be documented, tested, and approved before deployment.
Vulnerability and Patch Management
raia uses a proactive vulnerability and patch management process that prioritizes and implements patches based on classification. Such classification may include whether the severity is security-related or based on other additional factors. raia schedules third party penetration tests and/or performs internal assessments at least annually.
If you believe you have discovered a vulnerability, please email r@raiaai.com and raia will aim to address the vulnerability, if confirmed, as soon as possible.
Environment Separation
As necessary, raia maintains requirements and controls for the separation of development and production environments.
Source Code
raia controlled directories or repositories containing source code are secured from unauthorized access.
Logging and Monitoring
raia collects & monitors audit logs and alerts on key events stemming from production systems, applications, databases, servers, message queues, load balancers, and critical services, as well as IAM user and admin activities. raia manages logging solution(s) and/or SIEM tool(s) to collect event information of the aforementioned systems and activities. raia implements filters, parameters, and alarms to trigger alerts on logging events that deviate from established system and activity baselines. Logs are securely stored and archived for a minimum of 1 year to assist with potential forensic efforts.
Logs are made available to relevant team members for troubleshooting, auditing, and capacity planning activities. System and user activity logs may be utilized to assess the causes of incidents and problems. raia utilizes access control to prevent unauthorized access, deletion, or tampering of logging facilities and log information.
When events and alerts are generated from monitoring solutions and mechanisms, raia correlates those events and alerts across all sources to identify root causes and formally declare incidents, as necessary, in accordance with the Security Incident Response Policy and Change Management Policy.
Additionally, raia utilizes threat detection solution(s) to actively monitor and alert on network and application-based threats.
Business Continuity and Disaster Recovery
raia maintains a plan for continuous business operations if facilities, infrastructure or systems fail. The plan is tested, reviewed and updated at least annually.
Backup Policy
Backups are performed according to appropriate backup schedules to ensure critical systems, records, and configurations can be recovered in the event of a disaster or media failure.
Security Incident Response
raia maintains a plan that defines responsibilities, detection, and corrective actions during a security incident. The plan will be executed following the discovery of an incident such as system compromise, or unintended/unauthorized acquisition, access, use or release of non-public information. The plan is tested, reviewed and updated at least annually.
raia utilizes various monitoring and surveillance tools to detect security threats and incidents. Early detection and response can mitigate damages and minimize further risk to raia.
A message should be sent to r@raiaai.com if you believe there may be a security incident or threat.
Risk Management
raia requires a risk assessment to be performed at least annually. For risks identified during the process, raia must classify the risks and develop action plans to mitigate discovered risks.
Vendor Management
raia requires a vendor security assessment before third party products or services are used confirming the provider can maintain appropriate security and privacy controls. The review may include gathering applicable compliance audits (SOC 1, SOC 2, PCI DSS, HITRUST, ISO 27001, etc.) or other security compliance evidence. Agreements will be updated and amended as necessary when business, laws, and regulatory requirements change.
Privacy
Personal Data
raia personnel must treat personal data with appropriate security and handling and accommodate data subject requests, as required by applicable laws and regulations. No unauthorized personnel should have access to personal data.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is maintained by raia Management.
This document was last updated on May 7, 2026.
raia
Internal Control Policy
Purpose and Scope
This Internal Control Policy guides raia regarding the maintenance of an internal control system in order to safeguard the raia's assets against loss, promote operational efficiency, and encourage adherence to prescribed managerial policies.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems, or data. All personnel are required to read, accept, and follow all raia policies and plans.
Internal Control
Control Environment
raia senior management recognizes that a proper control environment provides the discipline and structure to help raia achieve its objectives. raia manages and maintains its internal controls through the use of the Secureframe platform.
Responsibility
raia senior management is responsible for ensuring that an adequate and effective internal control system exists at raia and that dedicated personnel are necessary for monitoring the performance of the internal control system. Senior management must establish and define responsible parties with accountability for overseeing and maintaining internal control processes and procedures. These lines of accountability should be reviewed annually to ensure that performance measures are being met. Corrective measures or changes in responsibility should be implemented as needed.
Annual Review
Internal control processes and procedures should be reviewed by raia senior management annually. Senior management may choose to sample a number of controls for review per year. Any outdated or non-operating procedures should be updated or removed. New controls should be implemented where appropriate.
Identified Deficiencies
Identified control failures or deficiencies and proposed corrective action plans for newly identified issues must be addressed and communicated to management.
Evaluation of Internal Controls
Internal control objectives are identified by relevance to the company, department, business line, or product.
As part of the evaluation process, a review of pertinent policies, procedures, and documentation will be completed to verify that applicable internal controls are operating effectively, and in line with business objectives.
A member of raia management or a designee will document the review of internal control policies and procedures and sign off on the review. Findings will be shared, as appropriate.
Identified issues are assessed to determine the impact to internal control. If necessary, corrective action plans are developed, tracked via documentation, and monitored until implementation.
Changes to Internal Controls
If a corrective action or change is required, raia management must assess the changes that could significantly impact the system of internal control including:
- External environment,
- Current business model,
- Leadership, and
- Business relationships (vendors, business partners, and other third-parties)
All changes must be approved by management before implementation. If the change is related to security of network and IT resources, the change must be approved and documented in accordance with documented change management procedures.
Changes to internal control activities must be communicated to all affected users in a timely manner.
Communication with External Third Parties
raia will communicate with external parties regarding the functioning of internal control (i.e. material changes to internal controls that affect nondisclosure agreement or contractual confidentiality and privacy provisions.).
raia will conduct an assessment to determine whether changes need to be communicated to and affirmed by the customer, partner, vendor, or other third parties. The manner in which the change is communicated must be in line with the significance of the change.
Communications with legal or regulatory implications must be reviewed and approved by management.
Exceptions
raia business needs, local situations, laws, and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Network Security Policy
Purpose and Scope
The purpose of this document is to define basic rules and requirements for network security and ensure the protection of information within and across networks and supporting information processing facilities.
This document applies to the security of all services, architecture, software and systems that make up raia's product/service, including our AI agent SaaS platform and proprietary framework.
Users of this document are all employees and applicable contractors who work on network engineering, security, and maintenance at raia.
Network Controls
raia manages, controls, and secures its networks, the connected systems, applications, and data-in-transit to safeguard against internal and external threats. This includes our cloud infrastructure hosted on Google Cloud.
Firewalls & Threat Defense
raia must utilize network firewalls, web application firewalls, and/or equivalent mechanisms to safeguard applicable internet connections, internal network zones, and applications from threats. raia configures appropriate firewall alerts and alarms for timely response and investigation. This also applies to applicable wireless networks.
raia ensures networking ports and protocols are restricted based on the principle of least functionality. Ports and network routes should only be open when there is proper business justification. Firewall configurations and rulesets are maintained. Firewall rules are implemented to minimize exposure to external threats. Significant changes to network services and configurations should be tracked in accordance with the Change Management Policy.
As an additional layer of defense, raia utilizes monitoring solutions, including Secureframe for agent-based device monitoring, to detect and alert on network-based intrusions and/or threats.
Network Diagramming
raia Management maintains network and data flow diagrams. Diagrams are reviewed and updated when significant network infrastructure changes occur.
Network Access Control
In addition to the Network Security Policy, raia establishes, documents, and reviews the Access Control and Termination Policy based on business and security requirements. This policy also encompasses network access control.
raia segregates networks based on the required groups of information services, users, and systems.
raia utilizes firewall configurations to restrict connections between untrusted networks and trusted networks.
Additionally, raia may utilize security groups and network access control lists (NACLs) to improve network security for individual virtual machines within our Google Cloud environment.
Network Engineering
raia implements security functions in a layered approach, minimizing interactions between layers of the design and avoiding any dependence by lower layers on the functionality or correctness of higher layers.
raia utilizes a defense-in-depth (DiD) architecture to protect the confidentiality, integrity, and availability of information systems and data, i.e. placing information systems that contain sensitive data in an internal network zone, segregated from the DMZ and other untrusted networks.
raia synchronizes clocks of all applicable information systems to the same time protocol to enforce consistent and accurate timestamping.
Network Service Level Agreements (SLAs)
Security mechanisms, service levels and management requirements of all network services should be identified and included in network services agreements, whether these services are provided in-house or outsourced to vendors such as Google Cloud.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Purpose
The performance evaluation process provides a means for discussing, planning and reviewing the performance of each team member. This provides both the employee and the department manager with the opportunity to discuss job tasks, identify and correct weaknesses, encourage and recognize strengths, and discuss methods for improving performance.
Performance evaluations may influence salaries, job responsibilities, promotions and transfers. It is critical that supervisors are objective in conducting performance reviews and in assigning overall performance ratings.
Eligibility
All employees who have been employed by raia for at least 1 year undergo an annual performance review. Managers are strongly encouraged to conduct reviews on a more frequent basis.
Performance Review Schedule
Performance evaluations are conducted annually with specific dates announced by Management. Each manager is responsible for the timely and equitable assessment of the performance and contribution of their team members. All performance reviews should be documented and retain to track an individual's performance over time.
Salary Increases
A performance evaluation does not always result in an automatic salary increase. The employee’s overall performance and salary level relative to position responsibilities must be evaluated to determine whether a salary increase is warranted.
Processes
Management will establish the format and timing of all review processes. The reviews may change from year to year and from person to person. The completed evaluations will be retained and documented.
Managers may not discuss any proposed action with the employee until all written approvals are obtained.
Management will review all salary increase/adjustment requests to ensure compliance with company policy and that they fall within the provided guidelines.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Purpose and Scope
The Physical Security Policy specifies the requirements for physically protecting assets and their data via physical controls and safeguards. Physical security is the first line of defense in information security, and without physical protections, virtual protections offer minimal security for assets and data. raia maintains reasonable steps to ensure that its facilities, information systems, and data are accessed only by authorized personnel or authorized third party visitors to prevent unauthorized access, damage, theft, and interference. All physical security requirements are applicable to both remote and in-office work. Key aspects of physical security include: perimeter and border security, entry controls, visitor management, restricted areas, equipment protection and maintenance, awareness and training, and risk management.
Perimeter and Border Security
raia facilities should be secured via external locked doors. raia facilities should be monitored via personnel, security cameras, and/or other mechanisms to detect potential security threats and respond to alerts.
Entry Controls
raia requires employees and applicable contractors to utilize access cards/keys to unlock external doors throughout all business hours. For facilities that have a security desk at the point of initial external access, external doors can be left unlocked as long as 1) employees and/or contractors authenticate prior to internal access via key/badge and 2) visitors are required to sign-in at the security desk prior to internal admittance.
Visitor Management
All visitors must sign-in with security prior to being allowed in internal office areas. Upon sign-in, the following visitor-specific information should be collected:
- Visitor name
- Visitor organization name (if applicable)
- Government-issued identification card information
Upon exit, the badge/nametag should be collected and the hr/min/sec timestamp for visitor exit should be captured. Visitor logs should be stored for at least 90 days via securely stored paper or digital records. Visitors that are unescorted should not have the ability to logically access restricted areas unless pre-authorization has been given by the approving manager. Visitors should receive a temporary badge or nametag - badge/nametag should be marked in a way that identifies them as a visitor. Any non-escorted or unauthorized visitors should be reported to the security team immediately.
Restricted Areas
Only authorized personnel shall be allowed entry into restricted areas. Restricted areas may include:
- Personal, confined offices
- Network closets
- Power & utilities closets
- Server rooms (as applicable)
Restricted areas must be secured via access badges/keys or security personnel.
Equipment
The following types of protection and monitoring equipment should be maintained at all times:
- Power utilities (e.g. generators, UPS)
- HVAC systems, including environmental sensors (thermometers and humidity sensors)
- Fire suppression systems
- Network, power, and telecommunications cabling
- On-premise servers and desktops (as applicable)
- Physical data backups
raia must securely store/protect the aforementioned equipment/assets from physical threats via proper access controls.
raia should maintain awareness of necessary maintenance schedules for the aforementioned equipment/assets. Maintenance should occur accordingly to prevent the failure of any of the aforementioned assets. Any third party/maintenance company that has access to a raia facility (e.g. night cleaning company) must receive security clearance from management and must follow all applicable parts of the security policies. Maintenance to and external movement of physical security components should be documented and tracked accordingly.
Risk Management
raia includes physical security within annual risk assessment scope.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
In its everyday business operations raia makes use of a variety of personal data, including data about:
- Current, past and prospective employees
- Customers
- Users of and visitors to its websites
- Subscribers
- Other stakeholders
In collecting and using this data, the organization is subject to a variety of legislation controlling how such activities may be carried out and the safeguards that must be put in place to protect it.
The purpose of this policy is to set out the relevant legislation and to describe the steps raia is taking to ensure that it complies with it. This control applies to all systems, people and processes that constitute the organization’s information systems, including board members, directors, employees, suppliers and other third parties who have access to raia systems.
Privacy and data protection policy
Applicable privacy legislation
The list below shows the main items of privacy legislation that apply to the countries (or groups of countries) and states within which raia operates.
- Argentina - Personal Data Protection Law (PDPL)
- Australia - Privacy Act
- Australia - Privacy and Personal Information Protection Act
- Brazil - General Data Protection Law (LGPD)
- Canada - Personal Information Protection and Electronic Documents Act (PIPEDA)
- Canada – Quebec - Act respecting the protection of personal information in the private sector
- European Union - General Data Protection Regulation (GDPR)
- Singapore - Personal Data Protection Act
- United Kingdom - UK GDPR Data Protection Act
- USA – California - California Consumer Privacy Act (CCPA)
raia has a legal obligation to comply with the provisions of this legislation at all times. Whilst there will be variations in these provisions, this policy establishes the key principles that are commonly required to be observed in such legislation.
Significant fines may be applicable if a breach is deemed to have occurred under the relevant privacy legislation, which is designed to protect the personal data of citizens of the country (or state, region or countries) involved. It is raia’s policy to ensure that our compliance with applicable legislation is clear and demonstrable at all times.
Definitions
The definitions used within privacy legislation vary and it is not appropriate to reproduce them all here. However, the common terms used within this policy are as follows:
Personal data: Any information that (a) can be used to identify the personal data principal to whom such information relates, or (b) is or might be directly or indirectly linked to a personal data principal.
Personal data principal: Natural person to whom the personal data relates. This term is also referred to as data subject.
Processing of personal data: Operation or set of operations performed upon personal data. Examples of processing operations of personal data include, but are not limited to, the collection, storage, alteration, retrieval, consultation, disclosure, anonymization, pseudonymization, dissemination or otherwise making available, deletion or destruction of personal data.
Data Controller: Privacy stakeholder (or privacy stakeholders) that determines the purposes and means for processing personal data other than natural persons who use data for personal purposes.
Data Processor: Privacy stakeholder that processes personal data on behalf of and in accordance with the instructions of a data controller.
Principles relating to processing of personal data
There are a number of fundamental principles upon which most privacy legislation is based. These are summarized as follows:
- Lawfulness, fairness and transparency - personal data shall be processed lawfully, fairly and in a transparent manner in relation to the personal data principal
- Purpose limitation – personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
- Data minimization – the personal data collected and stored shall be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed
- Accuracy – personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay
- Storage limitation – personal data shall be kept in a form which permits identification of personal data principals for no longer than is necessary for the purposes for which the personal data is processed
- Integrity and confidentiality – personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures
Processing of special categories of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited. Exception to this restriction is only applicable by lawful exceptions including but not limited to processing necessary to: reasons of public interest, purposes of preventive medicine, and defense or exercise of a legal claim.
raia will ensure that it complies with all these principles both within processing and as part of the introduction of new methods of system processing such as new IT systems.
Rights of the individual
The personal data principal also has rights with regard to their personal data. These will generally consist of:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- The right to object
- Rights in relation to automated decision making and profiling.
Each of these rights are supported by appropriate procedures within raia that allow the required action to be taken within the timescales stated in the applicable privacy legislation.
These timescales are shown in the list below:
- The right to be informed - When data is collected (if supplied by personal data principal) or within one month (if not supplied by personal data principal)
- The right of access - One month
- The right to rectification - One month
- The right to erasure - Without undue delay
- The right to restrict processing - Without undue delay
- The right to data portability - One month
- The right to object - On receipt of objection
- Rights in relation to automated decision making and profiling - Not specified
If raia does not take action on the request of the personal data principals, raia shall inform the personal data principal at the latest within one month of receipt of the request of the reasons for not taking action.
In cases where requests from a personal data principal are unfounded or excessive, raia may either: charge a reasonable fee taking into account the administrative costs of providing the information/communication/taking the action requested; or refuse to act on the request.
Furthermore, raia may request additional information necessary to confirm the identity of the personal data principal making the request. The information provided to personal data principals shall be comprehensible and in a clearly legible manner with an overview of the intended processing.
Moreover, raia shall take reasonable steps to inform relevant data controllers, data processors, and recipients (as applicable) of request of rectification/erasure/restriction of processing from the data principal, unless this proves impossible or involves disproportionate effort.
Lawfulness of processing
Depending on the legislation involved, there may be a number of alternative ways in which the lawfulness of a specific case of processing of personal data may be established. It is raia policy to identify the appropriate basis for processing and to document it, in accordance with the applicable legislation. The main options are described in brief in the following sections.
Consent
Where appropriate, raia will obtain consent from a personal data principal to collect and process their data. In cases of children being below the age specified in applicable legislation, parental consent will be obtained. Transparent information about our usage of their personal data will be provided to personal data principals at the time that consent is obtained and their rights regarding their data explained, such as the right to withdraw consent. This information will be provided in an accessible form, written in clear language and free of charge.
If the personal data is not obtained directly from the personal data principal, then this information will be provided to the personal data principal within a reasonable period after the data is obtained and definitely within one month.
Performance of a contract
Where the personal data collected and processed is required to fulfill a contract with the personal data principal, consent is not required. This will often be the case where the contract cannot be completed without the personal data in question, for example, a delivery cannot be made without an address.
Legal obligation
If the personal data is required to be collected and processed in order to comply with applicable law, then consent is not required. This may be the case for some data related to employment and taxation for example, and for many areas addressed by the public sector. For example, processing of personal data relating to criminal convictions and offenses or related security measures.
Vital interests of the personal data principal
In a case where the personal data is required to protect the vital interests of the personal data principal or of another natural person, then this may be used as the lawful basis of the processing. raia will retain reasonable, documented evidence that this is the case, whenever this reason is used as the lawful basis of the processing of personal data. As an example, this may be used in aspects of social care, particularly in the public sector.
Task carried out in the public interest
Where raia needs to perform a task that it believes is in the public interest or as part of an official duty then the personal data principal’s consent will not be requested. The assessment of the public interest or official duty will be documented and made available as evidence where required.
Legitimate interests
If the processing of specific personal data is in the legitimate interests of raia and is judged not to affect the rights and freedoms of the personal data principal in a significant way, then this may be defined as the lawful reason for the processing. Again, the reasoning behind this view will be documented.
Privacy by design
raia has adopted the principle of privacy by design and will ensure that the definition and planning of all new or significantly changed systems that collect, or process personal data will be subject to due consideration of privacy issues, including the completion of one or more privacy impact assessments.
The privacy impact assessment will include:
- Consideration of how as well as what types of personal data will be processed and for what purposes
- Assessment of whether the proposed processing of personal data is both necessary and proportionate to the purpose(s)
- Assessment of the risks to individuals in processing personal data
- What controls are necessary to address the identified risks and demonstrate compliance with applicable legislation
Use of techniques such as data minimization/pseudonymization/encryption will be considered where applicable and appropriate, including at the end of processing, and the mechanisms used to achieve them will be documented.
Where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, raia shall consult the supervisory authority prior to processing.
Contracts involving the processing of personal data
raia will ensure that all relationships it enters that involve the processing of personal data are subject to a documented contract that includes the specific information and terms required by the applicable legislation.
International transfers of personal data
Transfers of personal data between countries will be carefully reviewed prior to the transfer taking place to ensure that they fall within the limits imposed by the applicable legislation. This depends partly on the relevant authority’s judgment (for example in the case of the GDPR, the European Commission) as to the adequacy of the safeguards for personal data applicable in the receiving country and this may change over time.
Where an adequacy decision (or similar statement) does not exist for a destination country, an appropriate safeguard such as standard contractual clauses will be used, or a relevant exception identified as permitted under the applicable legislation.
Intra-group international data transfers will be subject to legally binding agreements referred to as Binding Corporate Rules (BCR) which provide enforceable rights for personal data principals.
Data protection officer
A defined role of Data Protection Officer (DPO) is generally required under privacy legislation if an organization is a public authority, if it performs large scale monitoring or if it processes particularly sensitive types of data on a large scale. The DPO is required to have an appropriate level of knowledge and can either be an in-house resource or outsourced to an appropriate service provider.
Based on these criteria, raia does not require a Data Protection Officer to be appointed.
Breach notification
It is raia's policy to be fair and proportionate when considering the actions to be taken to inform affected parties regarding breaches of personal data. In line with the applicable legislation, where a breach is known to have occurred which is likely to result in a risk to the rights and freedoms of individuals, the relevant supervisory authority will be informed within the specified timeframe.
GDPR Breach Notification (Article 33):
Where a personal data breach affects EU/EEA data subjects, raia must notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If notification is not achievable within 72 hours, the reasons for the delay must be documented and provided alongside the notification. The notification must describe the nature of the breach, approximate number of data subjects affected, likely consequences, and measures taken or proposed to mitigate the breach.
Communication to Data Subjects (Article 34):
Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, raia must communicate the breach to those individuals without undue delay, in clear and plain language.
Processor Obligations:
Where raia acts as a data processor, raia must notify the data controller without undue delay after becoming aware of a personal data breach, to enable the controller to fulfill its own 72-hour notification obligation.
All breach notification activities will be managed in accordance with the raia Security Incident Response Plan, which sets out the overall process of handling information security incidents, including the Regulatory Notification Requirements section and Notification Decision Matrix.
Under privacy legislation, the relevant authority may have the right to impose a range of fines. Under the GDPR, fines for breach notification failures may reach up to EUR 10 million or 2% of annual worldwide turnover (whichever is greater), and fines for violations of data processing principles may reach up to EUR 20 million or 4% of annual worldwide turnover (whichever is greater).
Data Protection Impact Assessments (DPIA)
raia shall conduct a Data Protection Impact Assessment prior to any processing that is likely to result in a high risk to the rights and freedoms of natural persons, including but not limited to:
- Systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significantly affect the natural person;
- Processing on a large scale of special categories of data or personal data relating to criminal convictions and offenses;
- Systematic monitoring of a publicly accessible area on a large scale.
The DPIA shall contain at minimum: a systematic description of the envisaged processing operations and purposes; an assessment of the necessity and proportionality of the processing; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks.
Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken to mitigate the risk, raia shall consult the relevant supervisory authority prior to processing.
Records of Processing Activities
In accordance with Article 30 of the GDPR, raia maintains records of processing activities under its responsibility. These records include:
- The name and contact details of raia and its designated privacy contact;
- The purposes of the processing;
- A description of the categories of data subjects and categories of personal data;
- The categories of recipients to whom personal data has been or will be disclosed;
- Where applicable, transfers of personal data to a third country, including identification of that country and the transfer safeguards in place;
- Where possible, the envisaged time limits for erasure of the different categories of data;
- Where possible, a general description of the technical and organizational security measures in place.
These records are maintained electronically and made available to the supervisory authority upon request.
Addressing compliance to applicable privacy legislation
The following actions are undertaken to ensure that raia complies at all times with the accountability principle of privacy legislation within the countries in which it operates:
- The legal basis for processing personal data is clear and unambiguous
- A Data Protection Officer is appointed with specific responsibility for data protection in the organization (if required)
- All staff involved in handling personal data understand their responsibilities for following good data protection practice
- Training in data protection has been provided to all staff
- Rules regarding consent are followed
- Routes are available to personal data principals wishing to exercise their rights regarding personal data and such inquiries are handled effectively
- Regular reviews of procedures involving personal data are carried out
- Privacy by design is adopted for all new or changed systems and processes
The following documentation of processing activities is recorded:
- Organization name and relevant details
- Purposes of the personal data processing
- Categories of individuals and personal data processed
- Categories of personal data recipients
- Agreements and mechanisms for transfers of personal data to other countries including details of controls in place
- Personal data retention schedules
- Relevant technical and organizational controls in place
These actions are reviewed on a regular basis as part of the management process concerned with privacy and data protection.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is maintained by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
This Processing Integrity Policy defines standards, procedures, and processes for data and system processing that is complete, accurate, and authorized to meet raia’s objectives. raia integrates with many different platforms and technologies as a software as a service (SaaS). It is critical that data is processed in a complete, accurate, and authorized fashion.
Roles & Responsibilities
This policy is guided by security requirements specific to raia, including applicable laws and regulations.
This policy applies to all raia personnel acting on behalf of raia or accessing its applications, infrastructure, systems and/or data. All personnel are required to read, accept, and follow all of raia policies and plans.
Additionally, this policy applies to all types of data that pass through raia. For more information on types of data within the raia environment, please refer to raia’s Data Classification Policy.
raia is the owner of all raia-issued hardware such as employee workstations and electronic systems and of the data stored in them or transmitted from them. Thus, any raia employees, contractors, clients, or anyone using raia hardware or software is required to follow and comply with this Processing Integrity Policy.
Processing Integrity Objectives
As raia integrates with many different softwares and technologies, raia aims to collect and maintain data accurately and completely. These objectives apply to all data defined and documented in the Data Classification Policy. raia has identified the following objectives around the protection and processing of data:
- raia will protect all data that enters, leaves, and/or is stored in the raia environment.
- This data will be encrypted at rest and in transit.
- Only authorized personnel will have access to this data.
- raia will communicate to and train all end users on the protection and security of relevant data. Training is done with an onboarding guide and support regarding control implementation.
- raia will review the Data Classification policy on an annual basis to ensure that security and handling policies and procedures for protecting and classifying sensitive data are up to date and accessible for all in-scope personnel.
In case of any processing errors, raia has identified and created the following policies and procedures to prevent, detect, and correct any processing errors.
raia automatically syncs to integrated technologies and platforms daily or manually at any point by the user and any processing errors will be captured during the daily automatic sync and immediately when the user triggers a manual sync.
If a processing error is found, the error will be reported by the user or internal personnel that monitor the processing errors, and a bug ticket will be created for the error in the internal ticketing tool (Confluence). If a user finds the error, they can report it via the internal feedback feature in raia or communicate the error to their Customer Success Manager who will create the ticket in the internal ticketing tool. If the user reports the error via the internal feedback feature, a support ticket will be created followed by a ticket in the internal ticketing tool to monitor and assess the issue.
Once a bug ticket has been created, it will be reviewed by the on-call engineer. The engineer will provide feedback on the issue and determine a response time for resolving.
If the bug is remediated, the engineer will notify the Customer Success Manager that the bug has been fixed and the ticket will be closed.
User account reviews are performed quarterly to control personnel access to client data. raia Management verifies appropriate permissions quarterly by reviewing the following systems: Google Cloud, Google Workspace, GitHub, OpenAI, Stripe, n8n. Any necessary changes are documented in a change ticket.
Audit log reviews are performed quarterly to detect any anomalies relevant to access to client data. raia Management reviews audit logs and notifications quarterly relevant to admin access and change activity in the following systems: Google Cloud, Google Workspace, GitHub, OpenAI, Stripe, n8n. Any potential anomalies detected follow the incident response process.
System Inputs
raia requires that system inputs contain the appropriate characteristics to ensure inputs and their data are properly entered into the system to maintain processing integrity. raia defines and requires the following characteristics for systems inputs:
- Complete
- Accurate
- Up-to-date
- Relevant
- Timely
- Reviewed and/or validated
Additionally, raia defines the following types of data inputs within the system:
- Manual information inputs including:
- Company information
- Any free form text box and additional details
- Automated data inputs from integrations (e.g., Google Workspace, Stripe, OpenAI)
raia has implemented the following system input controls to ensure that data inputs are properly configured to result in complete and accurate data:
- Edit checks for system inputs
- Input validations for system inputs
- Logging and monitoring of system inputs
- Access controls that ensure appropriate and authorized personnel are inputting data
System Processing
raia requires complete, accurate, and authorized system processing in order for the system and platform to function properly to provide raia’s intended service. In order to complete the system processing necessary for maintaining the integrity of the system’s data, raia must complete the following:
- System integrations must be configured properly and synced regularly in order for the correct data to be pulled and processed by raia.
- Integrations are fully tested for functionality prior to being released to users.
- Input criteria and remediation for manual uploads, in-platform tasks, and integration connections are provided to users to ensure the maintenance of processing integrity.
- Daily system syncs and the ability to sync at any time to ensure processing data is complete, accurate, and up to date.
- Logging and monitoring of integrations and data flows, including failed sync attempts or processes.
- Data pulled into raia via integrations are immediately stored within a database and cannot be changed by end users. raia provides users with in-platform functions to update, reorganize, and perform tasks against the data but cannot impact the integrity of the data.
- In the event of a processing error, Bugs can be reported by end users through the UI or by internal user through a shortcut ticket, are tracked to resolution, and follow the raia change management process.
System Outputs
raia requires that system and processing outputs are complete, accurate, and timely to ensure that raia personnel and customers are receiving complete and accurate data. raia has implemented the following system output controls to ensure that outputs are properly generated from the system to result in complete and accurate data:
- Access to the database where ingested data is stored is restricted only to specific raia administrators. Users do not have the ability to make direct changes to data once stored in the system and displayed. Changes to data are performed via specific functions within the application where any changes are logged.
- Data storage solutions containing sensitive customer data are encrypted at rest.
- Access controls to the raia ensure that customers control who has access to their data and information.
- Data Export functionality from the system is non-configurable, designed completely and accurately, and changes follow the change management process.
- raia exports are sampled and tested before being pushed to production.
- Logging and monitoring of system outputs and exports.
System Storage
raia requires that system and processing inputs, items in processing, and outputs are stored completely, accurately, and timely in accordance with system specifications required to protect all relevant data. raia has implemented the following system storage controls to ensure that data storage keeps raia and all relevant stakeholders data complete, accurate, and in a timely fashion:
- Logging and monitoring of system inputs, outputs, and storage.
- Successful integrations and/or any integration errors are logged, monitored and stored.
- Creation and maintenance of system storage logs and records.
- Full backups or versioning of the production environment are performed daily and retained in accordance with the Business Continuity and Disaster Recovery Policy (minimum 30 days for database backups).
- System logs and records are backed up to raia databases for at least 90 days.
- raia databases are protected from unauthorized use or actions. Databases are protected with database access controls providing access to only those that need it.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is maintained by raia Management.
This document was last updated on May 7, 2026.
raia
Risk Assessment and Treatment Policy
Purpose and Scope
This Risk Assessment Policy guides raia in performing risk assessments to account for threats, vulnerabilities, likelihood, and impact to raia assets, team members, customers, vendors, suppliers, and partners based upon the raia services considering security, availability, integrity, and confidentiality needs.
From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems, or data. All personnel are required to read, accept, and follow all raia policies and plans.
Risk Assessment Framework
raia conducts assessments of risk, which includes the likelihood and impact of risk from the unauthorized access, use, disclosure, disruption, modification and/or destruction of raia systems, applications, infrastructure, and data pertaining to raia's environment.
The risk assessment process is coordinated by raia Management, which includes the identification and evaluation of assets, threats, and vulnerabilities. Assets should be identified by respective asset owners, and the assessment of threats as well as the likelihood and criticality of potential vulnerability exploitation, should be performed by respective risk owners.
A risk assessment may include a review of:
- internal controls including policies, procedures, business processes, and technical security safeguards
- human resource practices related to hiring, termination, and discipline procedures
- facility controls
- exposure to theft
- systems and applications used to collect, store, process or transmit confidential data
- fraud
Risk Assessment Process
The risk assessment process should align with the following steps:
##### (1) Scoping Assets
In order to begin the risk assessment process, the assessor should determine the scope of what needs to be covered in the assessment. An effective assessment should be limited in its scope to the applicable assets.
Such scoping activities may include:
- Review inventory of critical system assets (hardware, software, facilities, etc.)
- Identification of data owners (electronic and non-electronic data)
- Identification of workforce members with access to stored data by hardware/software
- Mapping data flow through raia and vendor systems
- Conducting an inventory of data storage (including non-electronic data)
- System characterization (e.g. essential, non-essential)
##### (2) Identifying Threats and Vulnerabilities
Vulnerabilities and the related threats, both internal and external, to raia operations (including, but not limited to, its mission, functions, image, or reputation), assets, information, and individuals may be identified and documented as part of the raia risk assessment.
Threat
A threat is any circumstance or event with the potential to adversely impact organizational operations and assets, individuals, or other organizations, through an information system via unauthorized access, destruction, disclosure, or modification of information, and/or denial of service. [SP 800-30 Rev.1]
Vulnerability
A vulnerability is a weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source. [SP 800-30 Rev.1]
Vulnerabilities may be identified by the following:
- Vulnerability scanning and penetration tests
- Security control monitoring technologies
- Detected patterns, heuristics, or specific activities that indicate process gaps or technical weaknesses
- Internal and external audits
- External security vulnerabilities databases (e.g. CVE database) and reports
##### (3) Analyze Risks
For each risk, a risk owner has to be identified -- the person or organizational unit responsible for each risk. This person may or may not be the same as the asset owner. Once risk owners have been identified, it is necessary to assess consequences for each combination of threats and vulnerabilities for an individual asset if such a risk materializes:
Initial (or Inherent) Risk Likelihood Determination
How likely will an identified threat or vulnerability impact the organization given existing security controls?
The likelihood of occurrence is a weighted risk factor based on an analysis of the probability that a given threat is capable of exploiting a given vulnerability (or set of vulnerabilities). The likelihood factor is on a scale of 1 to 5, where 1 represents lowest likelihood and 5 represents highest likelihood.
Initial (or Inherent) Risk Impact Analysis
What is the cost if an identified threat or vulnerability impacts the organization given existing security controls?
The level of impact from a threat event is the magnitude of harm that can be expected to result from the consequences of unauthorized disclosure of information, unauthorized modification of information, unauthorized destruction of information, or loss of information or information system availability. The impact factor is on a scale of 1 to 5, where 1 represents lowest impact and 5 represents highest impact.
Initial (or Inherent) Risk Score
After the likelihood and impact analysis, a risk determination should be made. Risk is a function of the likelihood of a threat event's occurrence and potential adverse impact should the event occur. In order to determine risk score, raia multiplies impact * likelihood. The higher number equates to higher potential risk.
##### (4) Risk Treatment
For any critical or high risks identified during the risk assessment process, raia will immediately develop action plans to mitigate those risks which could include patching of vulnerable systems and/or applying other control activities. Risk responses shall consider obligations such as contractual agreements, laws, regulations and standards. The following items will have to be amended or defined based on discovered risk: IT policy and strategies, risk strategies, cost-effectiveness, type of protection, threats covered, risk levels, existing alternatives, and additional benefits derived from the treatment.
There are three possible responses to risk:
Risk Mitigation
Risk mitigation is the implementation of safeguards and countermeasures to reduce or eliminate vulnerabilities or threats.
Risk Transfer
Risk transfer is the placement of the cost of loss a risk represents onto another entity. This is accomplished by purchasing insurance and/or outsourcing.
Risk Acceptance
Acceptance of risk is the valuation by raia that the cost/benefit analysis of a possible safeguard and the determination that the cost of the countermeasure greatly outweighs the possible cost of loss due to a risk. Values under 3 are acceptable risks, while values 3+ are unacceptable risks. Unacceptable risks must be treated. On behalf of the risk owners, Senior Management will accept all residual risks.
##### (5) Calculate Residual Risks
Based on risk treatment decisions, plans, and net new compensating controls to be implemented, residual risks must be calculated, reassessing the respective initial risks' likelihoods and impacts.
##### (6) Reporting
raia Management or a designee is responsible for creating the risk assessment and treatment report and delivering results to senior management and other applicable personnel. This report shall include risk responses and documentation of risks that will be accepted by the organization such as threats or vulnerabilities that will likely impact the organization and with a low impact cost. All risk assessment reports must be documented and retained for a minimum of three years.
Unacceptable risks should be appropriately remediated or mitigated in accordance with the Change Management Policy and Vulnerability Management Policy.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee's or contractor's course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia Management or a designee is responsible for overseeing the successful completion of the risk assessment. Such risk assessments must be conducted at least annually or whenever there are significant changes to raia, its systems, or other conditions that may impact the security of raia such as the failure of a mission critical vendor or a security breach.
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
The purpose of this document is to define basic rules for secure development of software and systems.
This document is applied to the development and maintenance of all services, architecture, software and systems that make up raia's product/service.
Users of this document are all employees and applicable contractors who are involved with the development and maintenance of applications and systems at raia.
Secure Development and Maintenance
Securing the Development Environment
Access to the development environment is restricted only to authorized employees via logical access control. Development and production environments are logically separated.
Secure Engineering Principles
raia developers follow secure information system engineering practices for the development of new systems and for the maintenance of the existing systems. Minimum-security standards must be maintained and complied with when implementing new systems.
The same secure engineering principles are applied to outsourced development.
All developed code should be reviewed, utilizing the following peer review best practices: https://google.github.io/eng-practices/review/reviewer/.
Security Requirements Related to Public Networks
raia Management is responsible for defining security controls related to information in application services passing over public networks:
- the description of authentication systems to be used
- the description of how confidentiality and integrity of information is to be ensured
- the description of how non-repudiation of actions will be ensured
raia Management is responsible for defining controls for online transactions, which must include the following:
- how misrouting will be prevented
- how incomplete data transmission will be prevented
- how unauthorized message alteration will be prevented
- how unauthorized message duplication will be prevented
- how unauthorized data disclosure will be prevented
Repository and Version Control
raia utilizes GitHub as its code version control management tool to track and manage code development, testing, and merges with production. Changes in the development and during the maintenance of the systems must be done according to the Change Management Policy.
Protection of Test Data
Confidential and restricted data, as well as data that can be related to individual persons should not be used as test data, except as required for customer debugging, where approved by customers or where approved by management. On a similar note, test data should be restricted from entering the production environment.
Required Security Training
All engineers must periodically review the OWASP Top 10 as defined in the Change Management Policy.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
The Security Incident Response Plan provides a systematic incident response process for all Information Security Incident(s) (defined below) that affect any of raia's information technology systems, network, or data, including raia data held or services provided by third-party vendors or other service providers. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations.
This plan applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept and follow all raia policies and plans.
raia intends for this plan to:
- Define the raia security incident response process and provide step-by-step guidelines for establishing a timely, consistent, and repeatable incident response process.
- Assist raia and any applicable third parties (including vendors and partners) in quickly and efficiently responding to and recovering from different levels of information security incidents.
- Mitigate or minimize the effects of any information security incident on raia, its customers, employees, and others.
- Help raia consistently document the actions it takes in response to information security incidents.
“Information Security Incident” means an actual or reasonably suspected unauthorized use, disclosure, acquisition of, access to, corruption of, deletion, or other unauthorized processing of sensitive information that reasonably may compromise the privacy, confidentiality, integrity, or availability of that information.
Management
raia has a Security Response Team (SRT) consisting of predetermined employees from key departments at raia to manage security incidents. The SRT provides timely, organized, informed, and effective response to information security incidents to (a) avoid loss of or damage to the raia systems, network, and data; (b) minimize economic, reputational, or other harms to raia and its customers, employees, contractors and partners; and (c) manage litigation, enforcement, and other risks.
The SRT also oversees and coordinates the development, maintenance and testing of the plan, its distribution, and on-going updates of the plan. The Security Incident Response Plan is activated or enabled when a security incident occurs, and the SRT is responsible for evaluating the situation and responding accordingly. Depending on the severity of an incident the SRT may request engagement from various support teams to assist with the mitigation of the incident.
The SRT meets on a periodic basis for training, education, and review of the documented plan. The SRT consists of a core team with representatives from key raia groups and stakeholders. The current SRT roster includes raia Management (lead) and Thomas Hall, and may be contacted at r@raiaai.com.
Incident Response Process
The process outlined below should be followed by the appropriate Staff at raia in the event of an Information Security Incident. raia shall assign resources and adopt procedures to timely assess automated detection results, screen internal and external reports, and identify actual information security events. raia shall document each identified Information Security Incident.
Detection and Reporting
Automated Detection
raia may utilize automated detection means and other technical safeguards to automatically alert raia of incidents or potential incidents.
Report from raia Personnel
All raia personnel must report potential security incidents as follows:
- If you believe an incident occurred or may occur or may have identified a threat, vulnerability, or other security weakness, please report it to the following email immediately: r@raiaai.com;
- Provide all available information and data regarding the potential incident; and
- Once an incident has been submitted, please stop using the affected system, or any other potentially affected device until being given the okay from the SRT.
Report from External Source
External sources, including raia's customers, who claim to have information regarding an actual or alleged information security incident should be directed to r@raiaai.com.
Employees who receive emails or other communications from external sources regarding information security incidents that may affect raia or others, security vulnerabilities, or related issues should immediately report those communications to r@raiaai.com and should not interact with the source unless authorized.
Response Procedures
Overview
Responding to a data breach involves the following stages:
- Verification
- Assessment
- Containment and mitigation
- Post-breach response
All of the steps must be documented in an incident log and/or corrective action plan.
The data breach response is not purely linear, as these stages and the activities associated with these stages frequently overlap. raia must keep a record of any actions the organization takes in responding to the incident and preserve any evidence that may be relevant to any potential regulatory investigation or litigation including through use of an incident log, corrective action plan or other applicable documentation.
(1) Verification
The SRT will work with raia employees and contractors to identify the affected systems or hardware (such as a lost laptop or USB drive) and determine the nature of the data maintained in those systems or on the hardware.
The SRT will determine the threshold at which events are declared a security incident and officially initiate the incident response process.
(2) Assessment
Following verification of an Information Security Incident, the SRT will determine the level of response required based on the incident's characteristics, including affected systems and data, and potential risks and impact to raia and its customers, employees, or others.
The incident assessment must include what employees or contractors were affected, what customers were affected, and what data was potentially exfiltrated, modified, deleted or compromised.
The SRT will work together to assess a priority with respect to the incident based on factors such as whether:
- the incident exposed or is reasonably likely to have exposed data; or
- personally identifiable information was affected and the data elements possibly at risk, such as name or date of birth.
In addition, the SRT will consider whether the disclosure was:
- internal or external;
- caused by a company insider or outside actor; and/or
- the result of a malicious attack or an accident.
Lastly, if an information security breach has occurred, federal/country-wide law enforcement and local law enforcement should be contacted and informed of the breach. Law enforcement should be contacted in alignment with applicable breach notification laws. Internal and/or external general counsel should lead law enforcement communication efforts (in collaboration with SRT). If general counsel is not available, SRT should lead law enforcement communication efforts.
(3) Containment and Mitigation
As soon as raia has verified and assessed the breach, the SRT must take all necessary steps to contain the incident and return the raia systems back to their original state and limit further data loss or intrusion.
Such steps may include:
- Acting to stop the source or entity responsible, for example by:
- taking affected machines offline;
- segregating affected systems; or
- immediately securing the area if the breach involves a physical security breach.
- Determining whether other systems are under threat of immediate or future danger.
- Determining whether to implement additional technical measures to contain the data breach, such as changing locks, passwords, administrative rights, access codes, or passwords.
(4) Post-Breach Response
Any post-breach response including external and internal communications, notifications, and further inquiries will depend on the assessment and priority of the data breach.
raia will respond to confirmed disclosures affecting data subjects in accordance with breach notice periods defined in applicable laws and regulations.
As part of the final response based on the results of the breach, raia will review applicable access controls, policies and procedures and determine whether to take any actions to strengthen the organization's information security program.
Regulatory Notification Requirements
GDPR Breach Notification (EU/EEA Data Subjects)
Where a personal data breach involves the data of individuals located in the European Union or European Economic Area, raia must comply with the following notification obligations under the General Data Protection Regulation (EU) 2016/679:
Notification to Supervisory Authority (Article 33):
- raia must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons.
- If notification cannot be made within 72 hours, the notification must be accompanied by documented reasons for the delay.
- The notification must include:
- A description of the nature of the breach, including the categories and approximate number of data subjects and personal data records affected;
- The name and contact details of raia's designated privacy contact (r@raiaai.com);
- A description of the likely consequences of the breach; and
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
- Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.
Communication to Data Subjects (Article 34):
- When the breach is likely to result in a high risk to the rights and freedoms of affected individuals, raia must communicate the breach to those individuals without undue delay.
- The communication must describe in clear and plain language the nature of the breach and contain at minimum the contact point, likely consequences, and measures taken.
- Communication to data subjects is not required if:
- raia has implemented appropriate technical and organizational protection measures (e.g., encryption) that render the personal data unintelligible to unauthorized persons;
- raia has taken subsequent measures that ensure the high risk is no longer likely to materialize; or
- It would involve disproportionate effort, in which case a public communication or similar measure shall be used instead.
Processor Obligations:
Where raia acts as a data processor on behalf of a controller, raia must notify the controller without undue delay after becoming aware of a personal data breach, enabling the controller to meet its own 72-hour notification obligation.
NIS2 Directive Obligations (EU 2022/2555)
If raia is determined to fall within the scope of the NIS2 Directive as a digital service provider, the following incident reporting timeline applies for significant incidents:
- Early warning within 24 hours of becoming aware of a significant incident — indicating whether the incident is suspected of being caused by unlawful or malicious acts or could have cross-border impact;
- Incident notification within 72 hours — providing an initial assessment of the incident, including its severity and impact, and indicators of compromise where available;
- Final report within one month — including a detailed description of the incident, its root cause, mitigation measures applied, and any cross-border impact.
U.S. State Breach Notification Laws
raia will comply with all applicable U.S. state breach notification laws, which generally require notification to affected individuals within 30 to 60 days of discovery, depending on the jurisdiction. Where a breach affects 500 or more residents of a single state, notification to the state attorney general may also be required.
Notification Decision Matrix
The SRT shall use the following framework to determine notification obligations:
- Severity 1 (Critical): Confirmed breach of personal data affecting EU/EEA data subjects — initiate 72-hour GDPR notification clock immediately upon awareness. If NIS2 applies, issue early warning within 24 hours.
- Severity 2 (High): Confirmed breach of personal data affecting non-EU data subjects — follow applicable U.S. state notification timelines (generally 30-60 days).
- Severity 3 (Medium): Suspected breach under investigation — document timeline of awareness, begin assessment, and prepare notification materials in parallel.
- Severity 4 (Low): Security event contained with no evidence of data exfiltration — document in incident log; no external notification required unless risk assessment changes.
Key Learnings
As soon as the incident has been resolved, raia senior management should meet with the SRT and other relevant team members of the raia for a post-mortem to better understand the incident that took place, and determine how similar incidents may be prevented in the future.
The retrospective should be documented and key learnings from the retrospective should be presented to all appropriate team members in a timely manner.
Testing
Testing the plan annually is critical to ensuring the plan is effective and practical. Any gaps in the plan that are discovered during the testing phase will be addressed by raia management. All tests must be thoroughly documented.
Testing of this plan may be performed using the following methods:
Walkthroughs
Team members walk through the steps documented in this plan to confirm effectiveness, identify gaps, bottlenecks or other weaknesses. This walkthrough provides the opportunity to review the plan with a larger subset of people, allowing the team to draw upon an increased pool of knowledge and experiences. Team members should be familiar with procedures, equipment, and offsite facilities.
Table Top Exercises
An incident is simulated so normal operations will not be interrupted. Scenarios of various security incidents are used and this plan is put into action to determine its use and effectiveness.
Validated checklists can provide a reasonable level of assurance for many of these scenarios. Analyze the output of the previous tests carefully before the proposed simulation to ensure the lessons learned during the previous phases of the cycle have been applied.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
This plan will be reviewed and tested on an annual basis. Ensuring that the plan reflects ongoing changes to resources is crucial. This task includes updating the plan and revising this document to reflect updates; testing the updates; and training personnel. Test results will be documented and signed off by raia management. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is tested, maintained, approved and enforced by raia Management.
This document was last updated on May 7, 2026.
Purpose and Scope
This Vendor Management Policy guides raia in the execution, management, and termination of vendor and other third party agreements. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by employees and contractors acting on behalf of raia or accessing its applications, infrastructure, systems or data. All employees and contractors are required to read, accept and follow all raia policies and plans.
Vendor Management Process
raia will maintain a profile of all raia vendors that includes the vendor, their executed agreements, and the appropriate reviews and documentation of such vendors in accordance with this policy. Such reviews will be based on the risk level of each vendor.
In order for raia to contract with a new vendor, the following steps should be taken in advance:
(1) Request for New Vendor
If an employee or contractor of raia wishes to use the free or paid services of a new vendor, a request for such use must be submitted to your manager. As part of the submission, the request may include a completed raia new vendor request form.
(2) Risk Assessment and Due Diligence
Before entering into a contract and granting access to raia systems, a risk assessment and appropriate due diligence should be performed to determine the possible risk and impact to raia. Vendors should be separated into three risk tiers: High, Medium and Low. Risk assessments must occur for all high risk vendors.
In particular, a vendor security assessment should include answers to at least the following:
- Is the vendor of a customer-facing nature?
- Would the vendor be involved in receiving and storing confidential data. Examples include: customer data, employee data, regulatory data, or financial data?
- If so, where does the vendor use, access, and store such data?
- What security controls and measures does the vendor have in place?
- Request copies of all relevant security policies.
- Has the vendor undergone third party audits (such as SOC2, HITRUST, ISO)?
- If so, a review of such reports should be performed and identified weaknesses should be documented
- Is there a risk of regulatory scrutiny and customer harm associated with the vendor?
- What is the operational reliance on this vendor?
- Does this vendor present supply chain risk?
(3) Contract Review
A confidentiality agreement or services agreement containing a confidentiality clause or equivalent must be reviewed and executed prior to any use of services and sharing of confidential data between raia and any third-party.
Vendor agreements should at a minimum require that third-parties maintain the privacy and security of the confidential information stored, used, or disclosed on behalf of raia.
(4) Monitoring of Vendors
raia Management or a designee is responsible for annual or more frequent vendor reviews of high-risk vendors as determined by this policy.
raia must periodically review all third-party agreements to reasonably ensure that vendors remain in compliance with state and federal law and appropriately address any legal risk to raia. Agreements will be updated and amended as necessary when business and regulatory requirements change.
Annual reviews of vendors will be documented and retained for audit purposes. The annual review may include the gathering of applicable compliance audits (SOC 1, SOC 2, PCI DSS, HITRUST, ISO 27001, etc.) or other evidence of security compliance including performing a review of in-place security controls.
Results of the reviews must be compared to in-place agreements and/or SLAs to ensure that services are being provided as intended. If vendors are found to be in violation of any executed agreement(s), action plans and processes may be initiated to remedy the issue(s) or access to raia systems may be removed immediately.
(5) Termination of Vendors
Upon termination of a vendor's services, all confidential information stored by the vendor should be deleted and/or provided back to raia within 60 days.
(6) Assignment of Vendor Relationship Owners and Contacts
Vendors should be assigned internal relationship owners, and key external vendor contacts should be identified. Vendor contacts should be actively maintained in case any issues with the vendor's product or service arise.
GDPR and European Data Protection Requirements for Vendors
Where a vendor processes personal data on behalf of raia in relation to EU/EEA data subjects, the following additional requirements apply in accordance with the General Data Protection Regulation (GDPR):
Data Processing Agreements (Article 28)
raia must execute a Data Processing Agreement (DPA) with any vendor that processes personal data on its behalf. The DPA must specify:
- The subject matter and duration of the processing;
- The nature and purpose of the processing;
- The type of personal data and categories of data subjects;
- The obligations and rights of raia as controller.
The DPA must require the processor to:
- Process personal data only on documented instructions from raia;
- Ensure that persons authorized to process personal data have committed themselves to confidentiality;
- Take all measures required pursuant to Article 32 (security of processing);
- Not engage another processor without prior specific or general written authorization from raia;
- Assist raia in responding to data subject rights requests;
- Assist raia in ensuring compliance with breach notification obligations (including enabling raia to meet the 72-hour supervisory authority notification deadline);
- Delete or return all personal data at the end of the provision of services; and
- Make available to raia all information necessary to demonstrate compliance and allow for audits.
International Data Transfers
Where a vendor transfers personal data outside the EU/EEA, appropriate safeguards must be in place, including:
- An adequacy decision by the European Commission for the destination country;
- Standard Contractual Clauses (SCCs) approved by the European Commission; or
- Binding Corporate Rules approved by a supervisory authority.
raia must verify and document the transfer mechanism in use for each vendor that processes EU/EEA personal data in a third country.
Sub-processor Management
Vendors acting as processors must inform raia of any intended changes concerning the addition or replacement of sub-processors, giving raia the opportunity to object to such changes. Sub-processors must be bound by the same data protection obligations as set out in the DPA between raia and the vendor.
Vendor Security Controls
In order to protect raia, certain high-risk vendors may require additional controls such as:
- Not to use or further disclose confidential information other than as permitted or required by the agreement or as required by law
- Define the following service levels, where applicable:
- Service definitions,
- Delivery levels,
- Security controls,
- Aspects of service management, and
- Issues of liability, reliability of services, and response times
- Use appropriate safeguards to prevent use or disclosure of confidential information other than as provided for by the agreement
- Employ or implement appropriate administrative, physical, and technical security safeguards and privacy practices that meet the use and disclosure requirements of raia
- Require a prompt report of any inappropriate use, disclosure or breaches of confidential information
- Breach notification must include the following:
- names of breached individual(s) and contact information,
- date breach occurred and the date breach was discovered,
- information/data that was breached (e.g., social security number, name, address, etc.),
- mitigating activity undertaken to limit damages, and
- security controls that will be implemented to reasonably ensure a similar breach does not occur in the future
- Reasonably ensure that any agents, including subcontractors, who use and disclose confidential information will agree to the same restrictions and conditions that apply to raia and its team members.
- Require that third-parties coordinate, manage, and communicate changes to any services currently provided that could affect the security, availability, or integrity of covered data.
- Review warranties, indemnification and limitations of liability to determine maximum cost of risk.
- Upon termination of the agreement, if feasible, the service provider or vendor will return or destroy all confidential information, used or disclosed by the service provider on behalf of raia, in any form and will retain no copies of such information.
- If return or destruction is not feasible, the service provider may extend the agreement’s privacy and security protections to confidential information and limit further uses and disclosures to those purposes that make the return or destruction of confidential information infeasible.
- Authorize raia to terminate the agreement if raia determines the service provider or vendor has or is violating the executed agreement.
Exceptions
raia business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
raia
Vulnerability and Patch Management Policy
Purpose and Scope
This Vulnerability Management Policy defines an approach for vulnerability management to reduce system risks and integrate with patch management. From time to time, raia may update this policy and implement different levels of security controls for different information assets, based on risk and other considerations. This policy is guided by security requirements specific to raia including applicable laws and regulations.
This policy applies to all raia assets utilized by personnel acting on behalf of raia or accessing its applications, infrastructure, systems or data. All personnel are required to read, accept, and follow all raia policies and plans.
Vulnerability and Patch Management Program
raia maintains a vulnerability management process that is integrated into the Change Management Process.
raia may periodically test the security posture of its applications and systems through third-party testing as well as vulnerability scanning.
raia also monitors multiple security alert lists such as the CVE Database and US-CERT to get up to date information on the latest vulnerabilities and threats.
Third-Party Penetration and Vulnerability Tests
raia schedules third party security assessments, penetration tests, and/or dynamic analysis tests at least annually.
raia periodically performs vulnerability scans.
Identifying Vulnerabilities
raia reviews third-party penetration test reports and vulnerability scan results to verify vulnerabilities and determine impact.
Scoring Vulnerabilities
Vulnerabilities are derived from the Common Vulnerabilities and Exposures (CVE) Database and are documented and scored based upon the Common Vulnerability Scoring System (CVSS) standard.
Mitigating Vulnerabilities
If remediation is required, the appropriate team member at raia will be notified of the requirements to remediate or mitigate the vulnerability and the time frame of such requirement will depend on the severity and risk of the vulnerability. Such tracking of vulnerabilities must be done through the company's change management tool (e.g., GitHub, Confluence) and in accordance with the Change Management Process.
The information obtained from the vulnerability scanning process will be shared with appropriate personnel throughout the organization on a “need to know” basis to help eliminate similar vulnerabilities in other information systems.
Patching
All system components, software and production environments shall be protected from known vulnerabilities by installing applicable vendor supplied security patches. Other patches not designated as critical by the vendor shall be applied on a normal maintenance schedule as defined by normal systems maintenance and support operating procedures.
System and Non-Company Application Patching
Patching includes updates to all operating systems and third party applications as provided by the appropriate vendor.
raia Application Patching
raia applications are patched in accordance with the Change Management Policy. Patches deemed to be of a high or critical nature may be rolled out in a compressed schedule as set forth in such policy.
Patching Exceptions
Patching production systems (e.g. servers and enterprise applications) may require complex testing and installation procedures. In certain cases, risk mitigation rather than patching may be preferable. The risk mitigating alternative should be determined through a documented risk analysis.
Exceptions
raia business needs, local situations, laws, and regulations may occasionally call for an exception to this policy or any other raia policy. If an exception is needed, raia management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other raia policy or procedure may result in disciplinary action, up to and including termination of employment. raia reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. raia does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any personnel who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of raia as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
raia reviews and updates its security policies and plans to maintain organizational security objectives and meet regulatory requirements at least annually. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is approved by raia Management.
This document was last updated on May 7, 2026.
Last Updated: August 3, 2026
This Privacy Policy explains how Raia LLC ("raia," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information in connection with our websites, applications, AI platforms, and related services.
This Privacy Policy applies to websites and online properties related to raiaAI.com, including raiaAI.com, raiaCX.com, raiaCommand.com, raia2.com, raiaagent.com, raiabot.com, and related websites, as well as raia applications and services, including raia CX, raia Copilot, raia Chat, raia Command, raia Control, mobile applications associated with raia2, APIs, messaging features, AI agents, workflows, and related services.
Our services are intended for business use only and are not intended for individuals under 18 years old.
Use of our services is also governed by our Terms of Service and, where applicable, customer agreements, Data Processing Addendums, Business Associate Agreements, or other written agreements between raia and the customer.
1. Our Role: Controller and Processor
raia processes personal information in different roles depending on the context.
When we collect and use information for our own business purposes, such as operating our websites, managing accounts, billing, security, support, marketing, and business administration, raia acts as a data controller or business under applicable privacy laws.
When customers use raia to upload documents, configure AI agents, select or connect AI models or model providers, connect third-party systems, process conversations, send communications, or otherwise process data through the platform, raia generally acts as a data processor or service provider on behalf of the customer. In those cases, the customer determines the purposes, instructions, data sources, model and provider selections, recipients, workflows, deployment context, and legal basis for processing. Customers are responsible for their own privacy notices, consents, lawful basis, model and provider choices, and compliance obligations for their end users.
2. Personal Information We Collect
We may collect the following categories of personal information.
- Website, demo, and inquiry information. When someone visits our websites, requests a demo, submits a form, signs up for updates, or chats with us, we may collect name, email address, phone number, company name, demo request details, chat transcripts, and related inquiry information.
- Account information. When a business user creates or uses a raia account, we may collect name, email address, phone number, company name, password or authentication information, account status, role, permissions, and related account details.
- Subscription and billing information. We use Stripe to process payments. We may collect billing contact details, subscription records, invoice details, and payment-related metadata, but payment card information is processed by Stripe.
- Marketing and notification information. We may collect email addresses and related subscription preferences for newsletter signups, security alert signups, marketing communications, and opt-out records.
- Customer data processed through the platform. Customers may upload, connect, or generate data through raia, including documents selected by the customer for AI agent training, knowledge base materials, prompts, AI agent instructions, conversations with AI agents, training materials, model and provider selections, model versions, routing or fallback settings, endpoint and deployment configurations, workflows, automations, API/MCP-connected data, AI-generated responses, transcripts, model-interaction records, system logs, audit logs, API logs, workflow execution logs, and error/debug logs.
- AI agent conversation data. raia may process conversations between users and customer-configured AI agents across supported channels, including live chat, SMS/MMS, email, voice, APIs, and internal employee interactions through raia applications such as Copilot or Command. raia does not access personal email inboxes, personal SMS accounts, or unrelated personal communications. The data processed is limited to conversations and data routed through raia services and AI agents.
- Technical and usage information. We may collect IP address, browser type, device information, operating system, pages viewed, referring URLs, session data, login activity, API usage, event logs, product usage data, and similar technical information.
- Cookies and analytics data. Our websites use cookies and similar technologies, including Google Analytics, to understand website usage and improve our websites. We do not use advertising or retargeting pixels. Visitors may manage analytics cookies through our cookie consent banner, and we honor browser-based Global Privacy Control signals where applicable.
- We do not collect job applicant data through our websites.
3. Sensitive Information and Restricted Data
Customers may not upload or process sensitive personal information through raia unless expressly permitted under a separate written agreement with raia.
Sensitive information includes, for example, protected health information, financial account information, government identifiers, children's data, biometric data, criminal records, and other highly sensitive personal, employee, or customer records.
raia can support HIPAA-compliant use cases, but customers may not process protected health information through raia unless a separate written agreement, such as a Business Associate Agreement or equivalent agreement, is in place.
4. How We Use Personal Information
We use personal information to:
- provide, operate, maintain, secure, and improve our websites, applications, AI agents, APIs, and services;
- create, authenticate, administer, and support user accounts;
- process subscriptions, invoices, payments, and customer account administration;
- respond to inquiries, demo requests, support requests, privacy requests, and security requests;
- provide newsletters, security alerts, and marketing communications where permitted;
- allow customers to configure, train, deploy, monitor, and manage AI agents, AI models, model providers, workflows, integrations, and knowledge bases;
- route prompts, inputs, instructions, and related data to the AI models, model providers, endpoints, routing options, or deployment environments selected or authorized by the customer;
- process conversations with AI agents across supported channels;
- store customer-selected training documents, model and provider selections, routing and fallback settings, endpoint configurations, agent instructions, workflows, configurations, conversations, prompts, AI-generated responses, and logs;
- diagnose bugs, troubleshoot customer-specific issues, analyze customer-specific abuse or security issues, and maintain service integrity;
- monitor, prevent, and investigate fraud, spam, abuse, unauthorized access, and security incidents;
- comply with legal, contractual, and regulatory obligations;
- enforce our Terms of Service, customer agreements, and acceptable use requirements.
5. AI Data Handling, Customer Model Selection, and Model Training
5.1 No Public or Foundation-Model Training by raia
raia does not train public models or foundation models using customer data. raia does not use customer inputs, uploaded training documents, prompts, conversations, transcripts, or AI-generated outputs to train raia-owned models. raia does not train models.
Customer inputs and outputs may be used by the customer within that customer's own agent configuration, vector store, evaluations, reinforcement workflows, or knowledge base if the customer chooses to do so.
5.2 Customer-Selected Models and Providers
The raia platform may support multiple commercial, proprietary, customer-provided, third-party, open-source, or open-weight AI models and related tools. The customer selects and authorizes the model, provider, version, endpoint, deployment or hosting method, and any routing, fallback, or multi-model option used by the customer's AI agent. That selection or configuration instructs raia to transmit and process prompts, inputs, instructions, files, conversation data, outputs, and related metadata through the selected model, provider, endpoint, or environment as necessary to provide the configured functionality.
Different models, providers, versions, and deployment environments may have different data-use, retention, logging, security, access, location, and privacy practices. Those practices may change over time. Customers are responsible for evaluating whether their selected model, provider, endpoint, and deployment configuration are appropriate for the personal information and use case involved.
5.3 raia-Managed and Customer-Directed Providers
For AI/model providers made available under raia-managed enterprise or commercial arrangements, raia uses contractual and technical controls intended to prevent those providers from using raia customer data to train public or foundation models. Such providers may process customer data as necessary to provide model inference and related functionality, maintain security and service integrity, prevent abuse, comply with law, and perform other activities permitted by the applicable agreement.
If a customer independently connects, supplies, deploys, or authorizes an AI model, provider, endpoint, account, credential, API, integration, open-source model, open-weight model, or hosting environment outside raia's managed arrangements, the customer's selection determines the destination and applicable processing environment. The applicable provider terms, model license, deployment configuration, and data practices may govern processing performed outside raia's systems. raia does not control and cannot extend its own contractual commitments to processing performed independently by a customer-selected provider or environment. Customers are responsible for reviewing those terms and practices, configuring the connection appropriately, and providing any additional notices or obtaining any additional consents or lawful bases required for that processing.
For open-source or open-weight models, data handling depends on where and how the model is hosted and configured. A model may operate in an environment managed by raia, the customer, or another provider. The party controlling that environment may determine access controls, logging, retention, security updates, and processing locations. Customers should evaluate the selected host and configuration before routing personal information to such a model.
5.4 Support, Security, and Service Integrity
raia may process customer data for customer-specific support, troubleshooting, bug diagnosis, security, abuse detection, and service integrity. raia employees may review customer conversations or related customer content only with customer permission for troubleshooting or support. Customers can restrict raia employee access to their customer content at any time.
AI-generated outputs may be incomplete, inaccurate, biased, outdated, or unreliable. Customer responsibilities for selecting models, reviewing AI outputs, monitoring AI agents, and complying with applicable laws are addressed in our Terms of Service and applicable customer agreements.
6. Customer Responsibilities
Customers are responsible for the personal information they upload, connect, or process through raia.
Customers are responsible for:
- providing legally required privacy notices to their end users;
- obtaining all required consents and permissions before uploading, connecting, or processing personal information through raia;
- ensuring their use of raia complies with privacy, data protection, consumer protection, telemarketing, messaging, AI, and industry-specific laws;
- selecting and authorizing the AI models, model providers, versions, endpoints, deployment environments, routing options, and fallback options used by their AI agents;
- reviewing the applicable provider terms, model licenses, data practices, retention practices, security characteristics, processing locations, and known limitations of customer-selected models and providers;
- controlling the configuration, instructions, workflows, recipients, content, and outputs of their AI agents;
- determining whether their use of raia involves minors, sensitive information, regulated data, high-risk AI, or special legal obligations;
- responding to privacy requests from their own end users where the customer controls the relevant data.
- Customers may use raia to interact with minors only where the customer is responsible for providing required notices, obtaining parental or guardian consent where required, and complying with applicable laws.
7. Communications, SMS, Email, Voice, and Chat
raia may send marketing emails to prospects and customers. Recipients may unsubscribe using the unsubscribe link in the email or by visiting our website to unsubscribe. raia also may send service, account, security, legal, or transactional communications that are necessary to provide or secure the services.
SMS/MMS, voice, email, and live chat are platform features that customers may use through raia. raia does not use SMS for its own marketing. Customers control the content, recipients, timing, and lawful basis for communications sent through the platform. Customers are responsible for obtaining required consents and honoring opt-out requests.
raia uses providers such as Twilio and Mailgun to support SMS, voice, and email delivery.
8. Cookies and Analytics
Our websites use cookies and similar technologies. We currently use Google Analytics to understand website usage and improve our websites.
Our cookie consent banner includes analytics cookie controls. Visitors can manage or reject analytics cookies through the consent banner. We do not use advertising or retargeting pixels.
We also honor Global Privacy Control signals where applicable.
9. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients:
- Service providers and sub-processors. We use third-party providers to help operate, host, secure, support, and deliver our services. Current providers include Google Cloud, Cloudflare, Supabase, Lovable, Twilio, Mailgun, Stripe, OpenAI, Google, and Anthropic. We use Supabase and OpenAI for vector database or vector storage functions in connection with AI agent training and knowledge retrieval.
- AI/model providers selected or authorized by customers. We may disclose prompts, inputs, instructions, files, conversation data, outputs, and related metadata to the AI models, model providers, endpoints, accounts, routing services, or deployment environments selected or authorized by the customer as necessary to provide customer-configured AI agent functionality. For raia-managed providers, the processing is subject to raia's applicable enterprise or commercial terms. For a provider, model, endpoint, account, credential, open-source or open-weight deployment, or environment independently connected, supplied, or authorized by the customer, processing outside raia's systems may be governed by that provider's terms, the applicable model license, and the customer's configuration.
- Payment processors. We use Stripe for payment processing.
- Customer-directed integrations. Customers may connect third-party applications, AI models, model endpoints, accounts, APIs, or MCP tools through raia. When customers configure these connections, data may be exchanged with the systems and environments selected by the customer.
- Legal, compliance, and safety recipients. We may disclose information where required by law, subpoena, court order, legal process, government request, or to protect rights, safety, security, service integrity, and enforce our agreements.
- Business transfers. We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, subject to appropriate protections.
- raia does not sell personal information and does not share personal information for cross-context behavioral advertising.
Customers will receive notice by email before raia adds or changes sub-processors where required by contract or applicable law.
10. Data Retention
We retain personal information for the periods described below unless a customer agreement specifies otherwise.
- Account data. Account data is retained for 30 days after termination or account closure unless otherwise specified in an agreement.
- Customer-uploaded training documents, agent configurations, workflows, and knowledge base data. These are retained for 30 days after termination unless otherwise specified in an agreement.
- AI agent conversations, transcripts, prompts, and AI-generated responses. Customer conversations and AI responses are retained unless the customer configures the applicable agent to delete conversations after a specified number of days. In all cases, raia retains this data for a maximum of 5 years unless otherwise specified in an agreement.
- System logs, audit logs, API logs, workflow execution logs, and error/debug logs. Logs are retained for a maximum of 5 years unless otherwise specified in an agreement.
- External model providers and environments. The retention periods above apply to copies retained in raia's systems. A customer-selected model provider, endpoint, account, integration, or deployment environment may retain separate copies of inputs, outputs, logs, or metadata under the applicable provider terms, model license, customer configuration, or legal requirements. Customers are responsible for reviewing and configuring retention outside raia's systems when they independently connect, supply, or authorize that provider or environment.
- Backups. Backups may be retained for up to 90 days after data is deleted from active systems.
- Customers can delete their account, delete data within the application, and download data through available product functionality. Deleting data from raia may not delete a separate copy held in a customer-selected external system; customers must direct deletion requests to, or use the controls provided by, the applicable external provider where required.
11. Security
raia uses administrative, technical, and organizational safeguards designed to protect personal information. These include encryption in transit and at rest, MFA, SSO/SAML support, audit logs, internal least-privilege access controls, employee security and privacy training, and incident response procedures.
raia is SOC 2 certified.
No system is completely secure, and we cannot guarantee absolute security. Customers are responsible for maintaining the confidentiality of their credentials and properly configuring access controls within their accounts.
raia's safeguards apply to systems and processing controlled by raia. When a customer independently connects, supplies, hosts, or authorizes an external AI model, model provider, endpoint, account, credential, open-source or open-weight deployment, or other environment, the security of processing performed in that external environment depends on the provider, host, model, license, and customer configuration. Customers are responsible for evaluating and configuring those external security controls.
12. International Data Processing and Transfers
raia is based in Florida, United States. Customer data may be hosted and processed on Google Cloud infrastructure in North America and the European Union, depending on service configuration and operational needs.
We support customers in the United States, European Union, United Kingdom, and other jurisdictions. Where required for EU/UK data transfers, raia uses Standard Contractual Clauses or equivalent transfer safeguards.
A customer-selected AI model, model provider, endpoint, account, or deployment environment may process personal information in additional countries or regions determined by that provider or configuration. Customers are responsible for evaluating those locations and implementing any required transfer mechanism when they independently connect, supply, host, or authorize the applicable provider or environment.
Customers may enter into a Data Processing Addendum with raia where required or applicable.
13. Privacy Rights
Depending on where you are located, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information.
To exercise privacy rights, contact r+privacy@raiaai.com. raia verifies privacy requests by confirming access to the email account associated with the request.
raia does not accept privacy requests from authorized agents on behalf of users or customers unless required by applicable law.
Where raia acts as a processor or service provider for a customer, requests relating to customer-controlled data should generally be directed to the relevant customer. If raia receives a request involving customer-controlled data, we may direct the requestor to the customer or assist the customer in responding, as required by applicable law and contract.
14. California and U.S. State Privacy Rights
Residents of California and certain other U.S. states may have additional rights under applicable privacy laws, including the right to know what personal information we collect, use, disclose, or share; the right to access personal information; the right to correct inaccurate personal information; the right to delete personal information; the right to receive a portable copy of personal information; the right to opt out of sale or sharing; the right to limit certain uses of sensitive personal information; and the right not to be discriminated against for exercising privacy rights.
raia does not sell personal information and does not share personal information for cross-context behavioral advertising.
raia does not use sensitive personal information for purposes beyond providing the services requested by the customer unless there is a separate written agreement.
Requests may be submitted to r+privacy@raiaai.com.
15. EEA/UK Privacy Rights and Legal Bases
For individuals in the European Economic Area or United Kingdom, raia processes personal data under applicable legal bases, including performance of a contract, legitimate interests, consent, compliance with legal obligations, and, where applicable, processing on behalf of customers under customer instructions.
EEA/UK individuals may have rights to access, rectify, erase, restrict, object to processing, request portability, and lodge a complaint with a supervisory authority.
Requests may be submitted to r+privacy@raiaai.com.
16. Children and Minors
raia's websites and services are not directed to children under 13 or minors under 18. Users must be at least 18 years old to use the services.
Customers are responsible for determining whether their use of raia involves minors and for obtaining any required parental or guardian consent and providing legally required notices.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and provide notice where required by law or contract.
18. Contact Us
For privacy questions or requests, contact:
- Raia LLC
- 1751 Mound Street
- Sarasota, FL 34236
- Email: r+privacy@raiaai.com
For security questions or reports, contact:
Email: r+security@raiaai.com
Last Updated: August 3, 2026
These Terms of Service ("Terms") govern access to and use of the websites, applications, platforms, APIs, AI agents, workflows, messaging features, mobile applications, and related services provided by Raia LLC ("raia," "we," "us," or "our").
These Terms apply to websites and online properties related to raiaAI.com, including raiaAI.com, raiaCX.com, raiaCommand.com, raia2.com, raiaagent.com, raiabot.com, and related websites, as well as raia applications and services, including raia CX, raia Copilot, raia Chat, raia Command, raia Control, raia2 mobile applications, APIs, AI agents, workflows, messaging, integrations, and related services (collectively, the "Services").
By accessing or using the Services, Customer, Authorized Users, and Public Users agree to these Terms, as applicable. If you do not agree to these Terms, you may not access or use the Services.
If Customer has entered into a separately executed Master Services Agreement, Order Form, Data Processing Addendum, Business Associate Agreement, or other written agreement with raia, that written agreement will control to the extent it expressly conflicts with these Terms.
You control the data you place in raia. You are responsible for making sure you own it or have all rights, permissions, consents, notices, licenses, and lawful bases needed to upload, connect, import, and use it. This includes personal information, copyrighted or licensed material, confidential or proprietary information, and data imported from third-party applications. raia does not verify your rights to that data. If your data or your use of it causes a claim against raia, you must defend and indemnify raia as described in these Terms.
1. Definitions
Customer means the business entity that contracts with raia, creates or controls a workspace or account, builds or configures AI agents, uploads or connects data, connects third-party systems, and controls use of the Services.
Authorized User means an individual who registers, logs in, or is invited to access the raia platform on behalf of Customer, including Customer's employees, contractors, administrators, agents, or other authorized personnel.
Public User means any individual who interacts with a Customer's AI agent without logging into the raia platform, including through live chat, SMS/MMS, email, voice, embedded widgets, APIs, forms, or other public or customer-facing channels.
User means, as applicable, an Authorized User or Public User.
Customer Data means Customer-Sourced Data and all configurations, workflows, integrations, outputs, logs, files, and other information generated through or processed by the Services on behalf of Customer. For clarity, Customer Data includes all Imported Data and all data made available through Customer-authorized accounts, credentials, permissions, connectors, integrations, APIs, MCP tools, workflows, automations, and AI Agents, regardless of whether Customer or an Authorized User individually reviewed or selected each item before it was accessed or imported.
Customer-Sourced Data means all data, content, materials, records, files, documents, prompts, instructions, messages, communications, conversations, transcripts, images, audio, video, databases, datasets, personal information, Personal Data, Confidential Information, proprietary information, intellectual property, and other information that is submitted, uploaded, entered, transmitted, disclosed, collected, retrieved, accessed, copied, connected, synchronized, imported, ingested, generated, or otherwise made available to or through the Services by or at the direction of Customer, an Authorized User, a Public User interacting with Customer's AI Agent, or any person or system using Customer's account, credentials, permissions, integrations, workflows, or AI Agents. Customer-Sourced Data includes Imported Data and forms part of Customer Data.
Imported Data means Customer-Sourced Data accessed, retrieved, copied, transmitted, synchronized, imported, ingested, or otherwise made available from or through any third-party application, platform, account, service, database, data warehouse, file repository, website, API, MCP tool, connector, integration, OAuth authorization, webhook, automation, credential, or connected system, whether the import is initiated manually, automatically, periodically, by an AI Agent, or by a workflow.
Personal Data means information relating to an identified or identifiable individual, household, device, or other protected person or unit, including information defined as "personal data," "personal information," "personally identifiable information," or a similar term under applicable law.
Data Claim means any claim, demand, action, complaint, investigation, inquiry, subpoena, proceeding, allegation, takedown request, or notice by a data subject, content owner, intellectual-property owner, licensor, third-party application provider, regulator, governmental authority, or other third party arising out of or relating to Customer-Sourced Data or Customer's collection, acquisition, ownership, licensing, disclosure, upload, connection, synchronization, import, processing, use, sharing, retention, deletion, or other handling of Customer-Sourced Data.
AI Agent means an artificial intelligence agent, assistant, workflow, automation, chatbot, copilot, or related system configured, trained, deployed, or operated using the Services.
AI Tool means any artificial-intelligence model, foundation model, large language model, machine-learning system, or related AI-enabled retrieval system, model-serving service, API, integration, plugin, connector, MCP tool, automation tool, or other AI-enabled or algorithmic technology that is made available through, connected to, or used with the Services, whether provided, developed, operated, or hosted by raia, Customer, or a third party. AI Tools include proprietary, commercial, Customer-provided, open-source, and open-weight models and related technologies.
Applicable AI Laws means all laws, regulations, binding orders, and legally enforceable requirements governing the development, placing on the market, putting into service, deployment, provision, distribution, operation, use, monitoring, or output of an artificial intelligence system, including Regulation (EU) 2024/1689, as amended (the "EU AI Act"), and implementing or successor laws.
AI Transparency Feature means any notice, label, identifier, disclosure, watermark, metadata, provenance information, machine-readable marking, detectable signal, user-interface element, audible statement, log, technical safeguard, or other feature used to identify an AI interaction, disclose the person on whose behalf an AI Agent acts, identify AI-generated or manipulated content, preserve traceability, or support compliance with Applicable AI Laws.
EU Deployment means any making available, placing on the market, putting into service, deployment, use, or operation of an AI Agent in the European Union, or any use in which Customer directs, authorizes, or reasonably foresees that an AI Agent's output will be used in the European Union.
Intended Purpose means the use for which an AI Agent is intended by the applicable provider, including the specific context and conditions of use, as reflected in information supplied by Customer, product and technical documentation, instructions, promotional or sales materials, configurations, workflows, and other relevant communications.
Substantial Modification means a change to an AI Agent after it has been placed on the market or put into service that is not foreseen or planned in the applicable conformity assessment or documentation and that affects compliance with Applicable AI Laws or results in a modification to the Intended Purpose, including any change treated as a substantial modification under Applicable AI Laws.
2. Business Use; Eligibility
The Services are intended for business use only. Customers may use the Services only for lawful business purposes.
Customer and Authorized Users must be at least 18 years old to access or use the Services. By using the Services, Customer represents and warrants that Customer and its Authorized Users meet this requirement.
Public Users under 18 may interact with a Customer's AI Agent only where Customer is responsible for providing all legally required notices, obtaining parental or guardian consent where required, and complying with all applicable laws.
Customer is solely responsible for determining whether its use of the Services involves minors, children, students, patients, employees, consumers, regulated individuals, or other groups subject to special legal protections.
3. Account Registration and Security
Customer is responsible for all activity that occurs under its accounts, workspaces, AI Agents, API keys, credentials, integrations, and connected systems.
Customer must ensure that all Authorized Users use accurate account information and maintain the confidentiality of login credentials, API keys, authentication tokens, connected accounts, and integration permissions.
Customer is responsible for configuring permissions, access levels, security settings, integrations, and AI Agent capabilities appropriately. raia is not responsible for unauthorized access, misuse, data loss, agent activity, or third-party system activity caused by Customer misconfiguration, compromised credentials, Customer-selected integrations, or Customer's failure to secure its accounts.
Customer must promptly notify raia if Customer becomes aware of any unauthorized access, security incident, misuse, unlawful messaging, legal complaint, or suspected compromise involving Customer's account, AI Agents, integrations, workflows, Customer Data, Authorized Users, or Public Users.
Customer must also promptly notify raia of any actual or suspected serious AI incident, prohibited AI practice, material malfunction, discriminatory or fundamental-rights impact, removal or circumvention of an AI Transparency Feature, unauthorized Substantial Modification, or inquiry or complaint from an AI, consumer-protection, privacy, civil-rights, or market-surveillance authority.
4. Privacy and Data Protection
Use of the Services is subject to raia's Privacy Policy.
raia may process Customer Data as described in the Privacy Policy, applicable Data Processing Addendum, Customer agreement, and as necessary to provide, secure, support, troubleshoot, maintain, and improve the Services.
raia does not use Customer Data to train public AI models or foundation models.
Where Customer uses the Services to process personal information, Customer is responsible for providing all legally required notices, obtaining all required consents, establishing a lawful basis for processing, honoring applicable rights requests, and complying with all applicable privacy, data protection, consumer protection, messaging, and AI laws.
Where raia processes Customer Data on Customer's behalf, Customer remains responsible for the purposes, means, instructions, configuration, recipients, content, workflows, integrations, and legal basis for that processing.
5. Public Users and Customer Responsibilities
Public Users are subject to applicable parts of these Terms when they interact with AI Agents or other Services.
Customer is responsible for ensuring that Public Users receive appropriate notices, terms, consents, disclosures, and privacy information through Customer's own website, application, communication channel, or other appropriate means.
Customer is solely responsible for its relationship with Public Users, including all claims, requests, complaints, disputes, communications, notices, consents, opt-outs, and legal obligations arising from Public Users' interactions with Customer's AI Agents or Customer's use of the Services.
6. Customer Data; Imported Data; Rights and Responsibility
6.1 Ownership and limited processing right
As between Customer and raia, Customer retains all right, title, and interest, if any, in Customer Data. No provision of these Terms transfers to raia ownership of Customer Data. Customer grants raia, its affiliates, contractors, and subprocessors a worldwide, non-exclusive, royalty-free right and license during the applicable retention period to host, access, retrieve, copy, process, transmit, display, store, secure, support, troubleshoot, modify solely as technically necessary, and otherwise use Customer Data as necessary to provide, maintain, protect, and improve the Services; comply with Customer's instructions; enforce these Terms; and comply with applicable law.
6.2 Customer controls what data enters the Services
Customer controls and is solely responsible for determining what Customer-Sourced Data is submitted to, uploaded to, connected to, synchronized with, imported into, collected through, generated through, or otherwise made available to the Services. This responsibility applies whether Customer-Sourced Data is provided directly; submitted by an Authorized User or Public User; obtained through a Customer-controlled AI Agent, form, communication channel, or workflow; or accessed or imported from a third-party application through Customer-provided credentials, permissions, OAuth grants, APIs, MCP tools, connectors, integrations, webhooks, databases, automations, or connected systems.
Any instruction, configuration, authorization, credential, token, permission, integration, workflow, or other access mechanism supplied, enabled, approved, or maintained by Customer or an Authorized User constitutes Customer's instruction to raia to access and process the resulting Customer-Sourced Data within the authorized technical scope. Customer is responsible for reviewing and limiting that scope and for disabling access when it is no longer authorized or necessary.
6.3 Customer representations and warranties
Customer represents, warrants, and covenants, on its own behalf and on behalf of its Authorized Users, that throughout the period in which any Customer-Sourced Data is submitted to or processed through the Services:
- (a) Customer owns the Customer-Sourced Data or has obtained and will maintain all rights, licenses, permissions, authorizations, approvals, consents, and lawful bases necessary to collect, acquire, access, copy, disclose, upload, connect, synchronize, import, process, use, transmit, share, retain, and instruct raia to process the Customer-Sourced Data as contemplated by the Services and these Terms;
- (b) Customer has the right and authority to grant the rights and processing instructions granted to raia, its affiliates, contractors, and subprocessors under these Terms and any applicable written agreement;
- (c) Customer's and raia's authorized processing of Customer-Sourced Data will not infringe, misappropriate, or otherwise violate any copyright, patent, trademark, trade secret, database right, moral right, publicity right, privacy right, confidentiality obligation, contractual restriction, license term, third-party application term, or other right of any person or entity;
- (d) Customer has provided all notices and disclosures, honored all applicable rights, and obtained all consents, permissions, and lawful bases required under privacy, data-protection, communications, employment, consumer-protection, intellectual-property, confidentiality, records, sector-specific, and other applicable laws and agreements;
- (e) Customer will not submit or cause the Services to process Restricted Data except as expressly authorized in a fully executed written agreement with raia and in compliance with all required safeguards and instructions;
- (f) Customer-Sourced Data and Customer's instructions concerning it do not violate applicable law, a court order, a duty of confidentiality, a contractual obligation, or the terms governing any source system or third-party application;
- (g) Customer has not circumvented and will not circumvent access controls, technical restrictions, privacy settings, robots exclusions, provider policies, or authentication requirements to obtain or import Customer-Sourced Data; and
- (h) Customer will promptly notify raia and disable the affected access, integration, workflow, or AI Agent if any representation in this Section ceases to be true or if Customer receives a Data Claim.
The foregoing representations apply even if Customer does not own the Customer-Sourced Data, provided that Customer has all rights, licenses, permissions, consents, and lawful bases necessary for the contemplated processing. The mere fact that data is publicly accessible does not, by itself, satisfy Customer's obligations under this Section.
6.4 Personal, confidential, proprietary, and third-party information
Customer is solely responsible for identifying whether Customer-Sourced Data contains Personal Data, copyrighted material, trade secrets, Confidential Information, proprietary information, licensed content, employee or consumer records, regulated data, or information subject to third-party rights or restrictions. Before making such data available to the Services, Customer must determine that the contemplated processing is permitted and must implement all notices, consents, lawful bases, access controls, retention rules, contractual protections, and other safeguards required for that data.
Unless raia expressly agrees otherwise in a fully executed written agreement, raia does not act as Customer's legal adviser, records manager, copyright-clearance service, data broker, or licensing agent and does not determine whether Customer-Sourced Data may lawfully be collected, uploaded, imported, disclosed, or used.
6.5 No duty to investigate or verify Customer-Sourced Data
To the fullest extent permitted by law, raia has no duty to screen, monitor, investigate, authenticate, validate, license, clear, or verify Customer-Sourced Data or Customer's ownership of, authority over, rights in, notices concerning, consents for, lawful basis for, or compliance obligations relating to Customer-Sourced Data. raia may rely on Customer's representations, instructions, permissions, credentials, configurations, and authorizations without independent investigation.
Any review, filtering, moderation, support, security scan, takedown, restriction, removal, or other action by raia concerning Customer-Sourced Data is discretionary unless applicable law or a fully executed written agreement expressly requires otherwise. No such action creates a continuing monitoring duty, transfers responsibility from Customer to raia, constitutes approval or endorsement of Customer-Sourced Data, or waives any right or remedy of raia.
6.6 Customer assumption of Customer-Sourced Data risk
As between Customer and raia, and to the fullest extent permitted by law, Customer assumes all risk and responsibility arising out of or relating to Customer-Sourced Data, including its content, nature, source, provenance, acquisition, ownership, licensing, accuracy, quality, integrity, legality, confidentiality, privacy status, security classification, collection, disclosure, upload, connection, synchronization, import, use, processing instructions, recipients, retention, deletion, and compliance with applicable law or third-party obligations.
raia will not be responsible or liable for any Data Claim or other loss arising out of or relating to: (a) the presence or nature of Customer-Sourced Data in the Services; (b) Customer's decision or instruction to collect, submit, upload, connect, synchronize, import, disclose, process, use, share, retain, or delete Customer-Sourced Data; (c) any allegation that Customer-Sourced Data is copyrighted, proprietary, confidential, private, regulated, unlawfully obtained, improperly licensed, or owned by or subject to the rights of a third party; (d) Customer's lack or loss of any required ownership right, license, permission, consent, notice, authorization, approval, or lawful basis; or (e) Customer's or an Authorized User's selection, configuration, scope, or use of any third-party application, credential, permission, integration, API, MCP tool, connector, workflow, automation, or AI Agent.
This allocation applies regardless of whether raia knew or had reason to know the nature or source of Customer-Sourced Data; provided technical assistance in configuring an upload or integration; or the Services accessed, synchronized, or imported data automatically pursuant to a Customer-enabled instruction, permission, credential, integration, workflow, or AI Agent. Customer's responsibility is not reduced because Customer-Sourced Data is copied, converted, parsed, embedded, indexed, chunked, summarized, combined, transformed, retrieved, incorporated into a prompt or output, or otherwise processed through an AI model, AI Agent, retrieval system, integration, or workflow.
For clarity, this Section allocates responsibility for Customer-Sourced Data and Customer's right and decision to make it available to the Services. It does not eliminate any obligation expressly undertaken by raia concerning its own processing of Customer Data in a fully executed Data Processing Addendum or other written agreement. Any liability arising from such an obligation remains subject to Section 26 and all other applicable limitations, exclusions, defenses, and remedies, except to the extent applicable law prohibits limitation.
6.7 Claims, removal, and cooperation
Customer must notify raia promptly upon receiving or becoming aware of any Data Claim or allegation that Customer-Sourced Data may violate law, third-party rights, confidentiality, privacy, or an applicable agreement. Without limiting any other right, raia may block, remove, quarantine, disable, preserve, restrict, or suspend access to Customer-Sourced Data, an integration, workflow, AI Agent, account, or the Services if raia reasonably believes it presents legal, privacy, security, intellectual-property, provider, or reputational risk. raia is not required to adjudicate ownership or rights disputes before taking protective action.
Customer will, at its expense, promptly investigate and resolve each Data Claim; provide records demonstrating Customer's rights, notices, consents, permissions, licenses, and lawful bases; preserve relevant evidence; comply with lawful takedown, deletion, restriction, or rights requests; and cooperate with raia's response. raia's exercise or non-exercise of a removal or suspension right does not reduce Customer's obligations or liability.
In addition to its indemnification obligations, Customer will reimburse raia on written demand for reasonable out-of-pocket costs incurred in investigating, containing, preserving evidence concerning, responding to, or remediating Customer's breach of this Section or a Data Claim attributable to Customer-Sourced Data, including reasonable legal, forensic, provider, takedown, notification, and support costs, to the extent permitted by law. This reimbursement obligation applies whether or not a third party has filed a formal lawsuit.
6.8 Backups and copies
Customer is responsible for maintaining independent backups and archival copies of Customer-Sourced Data. Except as expressly stated in a fully executed written agreement, raia has no obligation to preserve, return, or recover Customer-Sourced Data beyond the retention and export functionality generally made available through the Services.
7. raia Technology and Ownership
raia owns and retains all rights in and to the Services, platform, software, user interfaces, APIs, models and model orchestration layers created by raia, templates, system prompts created by raia, prebuilt agent components, workflows created by raia, documentation, designs, tools, features, know-how, trademarks, service marks, logos, and underlying technology.
Except as expressly permitted by these Terms or a written agreement, Customer may not copy, reproduce, modify, distribute, sell, lease, sublicense, publish, display, exploit, reverse engineer, decompile, disassemble, scrape, extract, or attempt to derive source code, architecture, non-public APIs, platform design, proprietary prompts, proprietary workflows, or proprietary systems of raia.
Customer may use raia-created templates, prebuilt agent components, sample prompts, workflows, and documentation only within the Services unless raia gives prior written permission.
8. Feedback
Customer, Authorized Users, or Public Users may provide feedback, ideas, suggestions, comments, requests, or recommendations regarding the Services.
raia may use feedback without restriction or compensation, including to improve, develop, commercialize, or modify products, services, features, documentation, workflows, templates, or other offerings.
9. AI Services, Model Selection, Outputs, and Customer Responsibility
9.1 AI Tools supported through the Services
The Services may make available, access, route requests to, or interoperate with multiple AI Tools supplied by different developers, providers, operators, communities, and other third parties. Depending on the applicable Service and Customer configuration, available options may include hosted commercial models, proprietary models, Customer-provided models or endpoints, third-party model services, and open-source or open-weight models. Available AI Tools, providers, models, versions, deployment methods, routing methods, capabilities, and features may change as permitted by these Terms and any applicable written agreement.
9.2 Customer selection and authorization
Customer, and not raia, selects and authorizes the AI Tool or combination of AI Tools used by each Customer AI Agent, including the applicable provider, model, version, configuration, hosting or deployment method, and any available routing, fallback, or multi-model option. If Customer enables automatic routing, fallback, or a similar feature, Customer selects and authorizes the models made available under that configuration. Customer is responsible for confirming that each selection remains appropriate throughout the deployment.
Customer's selection, connection, credential, configuration, or authorization constitutes Customer's instruction to raia to route and process Customer Data through the selected AI Tool within the authorized technical scope. Customer is responsible for reviewing and limiting that scope and for changing or disabling a model, provider, endpoint, credential, routing option, or connection when it is no longer authorized or appropriate.
9.3 Model differences and unknown risks
Customer acknowledges that AI Tools may differ materially in their design, development or training methods, capabilities, limitations, accuracy, reliability, safety controls, content moderation, security, privacy practices, data use and retention, intellectual-property terms, licensing restrictions, provenance, auditability, regional availability, performance, cost, and legal or regulatory status. The behavior and output of an AI Tool may change between providers, models, versions, releases, configurations, deployments, data sources, or prompts. Some limitations, defects, vulnerabilities, biases, failure modes, or legal and operational risks may be undocumented, unknown, not reasonably foreseeable, or discovered only after testing or deployment.
Open-source and open-weight models may, depending on the model, source, maintainer, license, modification, and deployment, present additional or different risks. Those risks may include incomplete or inaccurate documentation; uncertain training-data, code, or model provenance; unclear, conflicting, or changing license obligations or use restrictions; limited or unavailable warranties, indemnification, support, safety testing, maintenance, or security updates; undisclosed vulnerabilities or malicious components; inconsistent forks or modifications; weaker, removed, or differently configured guardrails and content controls; and increased Customer responsibility for hosting, access control, monitoring, patching, incident response, and regulatory compliance.
The availability, compatibility, listing, integration, routing, default configuration, or technical support of an AI Tool through the Services does not constitute raia's endorsement, certification, legal clearance, security assurance, warranty, or determination that the AI Tool is accurate, safe, non-infringing, compliant, or suitable for Customer's use. Any documentation, comparison, recommendation, default setting, or technical assistance provided by raia is informational and does not replace Customer's independent evaluation.
Before selecting or deploying an AI Tool, Customer must review the applicable documentation, license terms, provider terms, data practices, security characteristics, Intended Purpose, restrictions, and known limitations; confirm that Customer has all necessary rights and approvals; and determine whether the AI Tool is appropriate for the Customer Data, users, deployment context, and intended outcomes. Customer must test each selected AI Tool before production use and on an ongoing basis after any material model, provider, version, configuration, data-source, or workflow change.
To the fullest extent permitted by law, Customer assumes the risks arising from Customer's selection, authorization, configuration, connection, deployment, or continued use of an AI Tool, including risks arising from model behavior, provider acts or omissions, open-source components, model updates, undocumented limitations, and incompatibility with Customer's intended use. This allocation does not excuse raia from an obligation expressly undertaken in a fully executed written agreement or from liability that cannot legally be limited. Sections 11, 25, and 26 also apply to Customer-selected AI Tools and providers.
9.4 Output limitations, professional review, and oversight
AI-generated outputs and AI Agent actions may be incomplete, inaccurate, misleading, biased, outdated, offensive, unlawful, unreliable, non-unique, or unsuitable for a particular purpose. raia does not warrant the truth, accuracy, legality, completeness, reliability, non-infringement, uniqueness, or fitness of any output or AI Agent action.
AI Tools and their outputs are not designed or intended to replace qualified professional judgment or advice. Customer must not treat or present an AI-generated output as legal, medical, financial, accounting, employment, insurance, safety, compliance, or other professional advice, or as a legally binding or verified determination, unless the output has been independently reviewed and approved by a qualified professional authorized to make the applicable determination.
Customer is solely responsible for reviewing, testing, validating, monitoring, approving, and determining the suitability of each selected AI Tool, AI Agent, output, workflow, integration, and action before publication, reliance, production deployment, or downstream use. Customer must independently review, test, and approve AI Agents before deploying them publicly or using them in production and must establish the human oversight required by Sections 14 and 14A.
Customer remains solely responsible for all AI Agents configured, trained, deployed, or operated by Customer, including all model selections, prompts, instructions, workflows, integrations, tools, connected systems, messages, outputs, actions, decisions, and Public User interactions. raia provides access to logs, conversations, and tools for reviewing AI Agent interactions. Customer is responsible for monitoring deployed AI Agents and taking appropriate action based on that monitoring.
9.5 Inputs, outputs, and intellectual-property considerations
Processing of Customer inputs and AI-generated outputs is governed by Sections 4 and 6, the Privacy Policy, any applicable Data Processing Addendum, and any other controlling written agreement. If Customer independently connects, supplies, or authorizes an AI Tool, account, credential, API, model, endpoint, integration, or provider outside raia's managed service arrangements, Customer is responsible for reviewing and accepting the applicable third-party terms, licenses, and data practices and for determining whether the connection is appropriate for Customer Data.
As between Customer and raia, Customer retains all right, title, and interest, if any, in Customer Data, including Customer inputs and AI-generated outputs, subject to raia's rights in raia Technology, the limited processing rights granted under Section 6, and any rights or restrictions imposed by applicable law or third-party terms. raia does not claim ownership of Customer inputs or outputs solely because they are processed through the Services.
Customer acknowledges that AI-generated output may not be unique and that the same or similar content may be generated for other users. raia does not represent or warrant that any output is protectable by intellectual-property law, non-infringing, exclusive, or available for Customer's intended use. Customer is responsible for determining what rights, permissions, notices, clearances, or licenses are required before using, publishing, distributing, commercializing, or relying on an output. Customer's representations, warranties, and responsibilities concerning Customer-Sourced Data under Section 6 apply to all inputs submitted to an AI Tool.
9.6 Model protection and competitive use
In addition to Sections 7 and 15, and except to the extent expressly enabled by documented Service functionality or authorized in a written agreement with raia, Customer, Authorized Users, and Public Users may not use the Services to discover or derive the model weights, parameters, architecture, algorithms, system prompts, training methods, safety systems, or other non-public components of an AI Tool.
Customer, Authorized Users, and Public Users may not use the Services, an AI Tool, or data or outputs obtained from the Services to create, train, fine-tune, distill, replicate, or improve any AI model, AI system, model-serving service, or competing product or service. This paragraph does not prohibit Customer from using Customer Data and outputs within Customer's own AI Agents, knowledge bases, evaluations, testing processes, or reinforcement workflows to the extent expressly enabled by the Services and permitted under Customer's applicable written agreement with raia.
9.7 Transparency, prohibited uses, and claims
Customer must comply with Sections 14, 14A, 15, and 15A concerning AI-law compliance, human oversight, transparency, content markings, acceptable use, and prohibited AI practices. Customer must not represent that an AI Agent is human, conceal the person on whose behalf it acts, remove required AI notices or content markings, or use an AI-generated output without any review, notice, label, or oversight required by Applicable AI Laws. Customer's responsibility for its configuration and use does not eliminate any non-waivable obligation imposed directly on raia.
Customer is responsible for claims arising from Customer's selection or use of an AI Tool and from Customer's inputs, outputs, AI Agents, publications, decisions, or actions, subject to Sections 6 and 27.
10. AI Agent Actions, Integrations, APIs, and MCP
Customer may configure AI Agents to interact with third-party systems, APIs, integrations, MCP tools, databases, workflows, communication channels, and other connected services.
Customer is solely responsible for authorizing, configuring, testing, monitoring, and approving any AI Agent actions taken through connected systems, APIs, integrations, tools, or MCP connections.
Customer is solely responsible for all actions taken by Customer's AI Agents, whether those actions are initiated by Customer, Authorized Users, Public Users, workflows, integrations, APIs, automations, or AI-generated instructions.
Customer authorizes raia to rely on and act upon credentials, tokens, OAuth grants, API keys, permissions, access scopes, mappings, filters, synchronization settings, workflows, and instructions supplied or enabled by Customer or an Authorized User. Customer is solely responsible for confirming that each third-party application permits the contemplated access, import, synchronization, storage, transfer, and downstream use of Imported Data and for ensuring that the enabled scope is no broader than necessary.
raia does not control and is not responsible for the content, ownership, licensing, legality, privacy status, confidentiality, accuracy, availability, or conduct of third-party applications or Imported Data. Customer's responsibility applies to automatically or periodically synchronized data and to data selected or imported by an AI Agent, workflow, or automation operating under Customer's account, instructions, credentials, or permissions.
raia is not responsible for Customer's third-party applications, integrations, MCP tools, connected systems, APIs, credentials, or downstream actions taken through such systems.
11. Third-Party Services and AI Models
The Services may depend on third-party providers, including cloud infrastructure, communications providers, email providers, payment processors, AI model providers, database providers, and integration providers.
raia may add, change, substitute, upgrade, downgrade, or modify third-party providers, AI models, model routing, infrastructure, or components at any time, provided the core Services remain materially similar.
raia may add new AI models or providers without advance notice.
Customer remains responsible under Section 9 for selecting and authorizing the AI Tools used by Customer's AI Agents from the options then available through the Services. A change to available models, providers, or routing functionality does not, by itself, authorize raia to process Customer Data through an AI Tool Customer has not selected or enabled, except where Customer has enabled automatic routing, fallback, or a multi-model option or a fully executed written agreement expressly provides for raia-managed model selection or routing.
raia will provide 90 days' advance notice before removing an available AI model from the Services, unless earlier removal or suspension is required because of law, regulation, provider policy, provider discontinuation, security risk, abuse risk, service outage, emergency, or other circumstances outside raia's reasonable control.
raia may temporarily disable, restrict, or stop offering a third-party AI model, provider, integration, feature, or component immediately if required by law, provider policy, security risk, outage, abuse risk, platform instability, or emergency.
raia is not responsible for failures, outages, changes, limitations, terms, policies, or acts or omissions of third-party providers, except as expressly provided in a separate written agreement.
12. Messaging, Communications, and Customer Compliance
The Services may allow Customer to send, receive, automate, or process communications through email, SMS/MMS, voice, live chat, APIs, and other channels.
Customer is solely responsible for ensuring that all communications sent, received, or processed through the Services comply with applicable laws and industry rules, including the Telephone Consumer Protection Act, CAN-SPAM Act, GDPR, ePrivacy Directive, CASL, CTIA guidelines, state telemarketing laws, privacy laws, consumer protection laws, and other applicable rules.
Customer must obtain all legally required consents before sending or initiating communications through the Services.
Customer must honor all legally required opt-outs, unsubscribe requests, revocations of consent, and communication preferences.
Customer is responsible for ensuring that message content is lawful, truthful, non-deceptive, non-harassing, and compliant with applicable law.
Customer may not use the Services to send spam, unlawful marketing, harassment, deceptive content, abusive communications, illegal solicitations, or prohibited messages.
Customer acknowledges that violation of this section may result in immediate suspension or termination and may trigger Customer's indemnification obligations.
13. Restricted and Prohibited Data
Customer may not upload, connect, process, transmit, or generate sensitive or regulated data through the Services unless expressly permitted under a separate written agreement with raia.
Restricted data includes protected health information, financial account information, government identifiers, biometric data, children's data, criminal records, and other highly sensitive personal, employee, consumer, or customer records.
raia can support HIPAA-compliant use cases, but Customer may not process protected health information through the Services unless a separate written agreement, such as a Business Associate Agreement, is in place.
Customer is solely responsible for determining whether Customer Data is subject to industry-specific or regulated-data obligations.
Customer's failure to identify Customer-Sourced Data as Restricted Data does not authorize its processing and does not transfer responsibility to raia. Any product capability, security feature, model, integration, or technical ability to process a data type does not constitute raia's legal approval to process that data or a waiver of the requirement for a separate written agreement.
If Customer submits Restricted Data without the required written agreement, Customer does so in material breach of these Terms and at its sole risk. raia may immediately suspend processing, isolate or delete the affected data where legally and technically appropriate, and require Customer to reimburse reasonable investigation, containment, remediation, notification, and response costs to the extent arising from Customer's breach, in addition to Customer's indemnification obligations.
14. AI Law, EU Use, and High-Risk or Regulated Uses
14.1 Compliance by role
Each party will comply with the obligations imposed on that party by Applicable AI Laws in the role or roles legally assigned to it. Contractual labels or allocations do not change a party's status as a provider, deployer, importer, distributor, product manufacturer, authorized representative, or other operator where that status is determined by Applicable AI Laws.
Customer is responsible for its decisions concerning the purposes, Intended Purpose, configuration, instructions, deployment context, users, recipients, workflows, connected systems, use of outputs, and manner in which Customer deploys or operates an AI Agent, and for all obligations Applicable AI Laws impose on Customer in connection with those decisions.
14.2 Required Customer information
Before an AI Agent is deployed and promptly upon any change, Customer must provide raia with complete and accurate information reasonably requested to assess legal requirements, including:
- (a) the AI Agent's Intended Purpose and material functionality;
- (b) all countries or regions in which the AI Agent will be offered, deployed, used, or reasonably expected to produce outputs that will be used;
- (c) the natural persons, businesses, groups, and reasonably foreseeable vulnerable persons with whom or about whom the AI Agent will interact or make, support, influence, or inform decisions;
- (d) whether the use involves profiling, biometric identification or categorisation, emotion recognition, employment, worker management, education, essential services, credit, insurance, housing, healthcare, law enforcement, migration, justice, democratic processes, legal or similarly significant effects, or another high-risk or regulated context;
- (e) whether the AI Agent may generate or manipulate audio, image, video, or text content, including deepfakes or text intended to inform the public on matters of public interest;
- (f) the person or entity on whose behalf the AI Agent acts and the name or other identification that must be disclosed to persons interacting with it;
- (g) any Customer modification, rebranding, retraining, fine-tuning, integration, change in instructions, change in data sources, or change in Intended Purpose; and
- (h) other information reasonably necessary for raia to support compliance with Applicable AI Laws.
Customer represents and warrants that this information is accurate, complete, and not misleading. Customer must notify raia before implementing a material change and must not conceal, mischaracterize, or omit a use that may be prohibited, high-risk, regulated, or subject to a transparency obligation.
14.3 EU Deployment notice
Customer must notify raia in writing before any EU Deployment unless Customer has already identified that EU Deployment in an Order Form or other writing accepted by raia. Customer must promptly notify raia if an AI Agent or its output begins to be used in the European Union in a manner Customer directs, authorizes, or reasonably foresees.
14.4 High-risk and regulated uses
Customer may not configure, market, rebrand, substantially modify, deploy, or operate an AI Agent for a high-risk, regulated, safety-critical, or legally significant use without raia's explicit prior written authorization and execution of any AI compliance addendum, Order Form, or other terms required by raia.
Restricted uses include, without limitation, uses involving employment or worker management; education or vocational access or assessment; eligibility for essential private or public services; creditworthiness or credit scoring; life or health insurance risk assessment or pricing; emergency-call evaluation or dispatch prioritisation; biometric identification or categorisation; emotion recognition; law enforcement; migration, asylum, or border control; administration of justice; democratic processes; healthcare diagnosis or treatment; or decisions producing legal or similarly significant effects.
Customer must not deploy or continue using an AI Agent where raia has denied, suspended, conditioned, or withdrawn authorization for the relevant use. raia's authorization does not constitute a representation, warranty, certification, or legal determination that the use is lawful, non-high-risk, compliant, accurate, or suitable.
14.5 Change of purpose, rebranding, and substantial modification
Customer must not change an AI Agent's Intended Purpose, place or put it into service under Customer's name or trademark in a manner that changes the legally responsible provider, or make a Substantial Modification without prior written notice to and approval from raia.
To the extent Customer becomes or is treated as a provider or other operator under Applicable AI Laws because of Customer's rebranding, Intended Purpose, modification, integration, or deployment, Customer will timely perform the obligations applicable to that role. Customer will not state or imply that raia has completed any required classification, conformity assessment, registration, declaration, or certification for Customer's modified or repurposed system unless raia expressly confirms that fact in writing.
14.6 Compliance controls
raia may introduce, enable, update, require, or enforce AI Transparency Features, logging, monitoring, use restrictions, geofencing, technical documentation, human-oversight mechanisms, output controls, warnings, notices, labels, rate limits, model restrictions, or other safeguards reasonably designed to comply with Applicable AI Laws or reduce legal, safety, security, or fundamental-rights risk.
Customer must implement reasonable instructions raia provides concerning those safeguards and must not disable, bypass, obscure, remove, interfere with, or misrepresent them. A change reasonably necessary to comply with Applicable AI Laws or address a material AI risk will not, by itself, constitute a breach or material reduction of the Services.
14.7 Cooperation, records, and regulatory communications
Customer must maintain records appropriate to its role and use, including material configurations, Intended Purpose, instructions, data sources, human-oversight measures, validation and testing results, deployment locations, notices, approvals, monitoring results, and incidents. Customer must provide relevant records and reasonable cooperation upon request where necessary for raia to assess classification, fulfill legal obligations, respond to an authority, investigate an incident, conduct post-market monitoring, or defend a claim.
Customer must promptly notify raia of any actual or suspected serious AI incident, prohibited practice, material malfunction, discriminatory or fundamental-rights impact, unauthorized change, circumvention of a safeguard, regulatory inquiry, inspection, complaint, or order relating to an AI Agent or Customer's use of the Services. Customer must preserve relevant evidence and not make a submission on raia's behalf without raia's written authorization.
14A. AI Transparency and Customer Deployer Duties
14A.1 In-context disclosure of AI interaction
Customer acknowledges that a disclosure contained only in these Terms, a privacy policy, a hyperlink, or general documentation may not satisfy an in-context AI transparency requirement.
Customer must provide raia with accurate information identifying the person or entity on whose behalf each AI Agent acts. Customer will not configure or present an AI Agent as a human or use an identity, voice, image, interface, or statement likely to mislead a natural person about the Agent's artificial nature or the principal on whose behalf it acts.
Where Customer controls or customizes a website, application, widget, telephone flow, email, SMS/MMS message, account, channel, integration, interface, greeting, or other context through which an AI Agent interacts with a natural person, Customer must ensure that all notices supplied or required by raia are presented clearly and distinguishably, in an accessible form, at or before the first interaction and at each new interaction or other time required by Applicable AI Laws. Customer must ensure that an AI Agent discloses both its artificial nature and the person on whose behalf it acts where required by Applicable AI Laws.
14A.2 Preservation of AI Transparency Features
Customer must not remove, alter, disable, suppress, conceal, obscure, strip, overwrite, or interfere with an AI Transparency Feature. Customer must preserve applicable notices, labels, machine-readable markings, metadata, provenance information, watermarks, and detectable signals when Customer downloads, exports, publishes, distributes, transforms, transmits, or routes AI-generated or manipulated content through an integration or downstream system, to the extent technically feasible and required by Applicable AI Laws.
Customer must not instruct or enable an Authorized User, Public User, contractor, application, integration, model, or downstream recipient to circumvent an AI Transparency Feature. Customer must promptly report any removal, loss, failure, or circumvention of such a feature.
14A.3 Customer labelling and notification duties
To the extent Customer is a deployer or otherwise responsible under Applicable AI Laws, Customer must provide all legally required, clear, distinguishable, timely, and accessible notices and labels, including notices to natural persons exposed to emotion-recognition or biometric-categorisation systems and labels for deepfake content or qualifying AI-generated or manipulated text published to inform the public on matters of public interest.
Customer must ensure that required labels remain visible to the targeted and reasonably foreseeable audience at first exposure and throughout downstream publication or distribution where required. Customer is responsible for determining whether an exception applies and for documenting the facts supporting that exception.
14A.4 Human oversight and decisions
Customer must establish and maintain human oversight appropriate to the Intended Purpose and risk of the AI Agent. Customer must not use an AI Agent or its output as the sole basis for a decision producing legal or similarly significant effects unless expressly authorized by raia in writing and permitted by Applicable AI Laws. Customer is responsible for ensuring that human reviewers have sufficient authority, competence, training, information, and time to understand limitations, identify anomalies or bias, disregard or override output, and stop use where necessary.
14A.5 AI literacy
Customer will take measures appropriate to its role, context, and risk to support the development of AI literacy among personnel and other persons operating or using AI Agents on Customer's behalf, taking into account their technical knowledge, experience, education, training, the use context, and the persons or groups on whom the AI Agent is used. Customer is not required by this clause to guarantee any specific level of AI literacy for any individual.
14A.6 Non-transfer of raia obligations
Nothing in this Section transfers to Customer a duty that Applicable AI Laws impose on raia and do not permit raia to delegate. Customer's duties under this Section apply to Customer's own role, conduct, information, controlled channels, modifications, deployments, and downstream use and are intended to enable each party to fulfill its respective obligations.
15. Acceptable Use
Customer, Authorized Users, and Public Users may not use the Services to:
- violate any law, regulation, contract, third-party right, or industry rule;
- infringe, misappropriate, or violate intellectual property, privacy, publicity, confidentiality, or other rights;
- upload, import, synchronize, disclose, process, use, or share data unless Customer owns it or possesses all rights, licenses, permissions, notices, consents, authorizations, approvals, and lawful bases required for the contemplated processing;
- access or import data from a third-party application in violation of that application's terms, access controls, license restrictions, privacy settings, or the rights of its users or other third parties;
- submit or process trade secrets, confidential information, proprietary information, copyrighted content, or Personal Data belonging to another person except as authorized by law and by the applicable owner, licensor, data subject, or other rights holder;
- instruct an AI Agent, integration, workflow, scraper, connector, API, or MCP tool to collect or obtain data that Customer would not be legally permitted to collect or obtain directly;
- upload or transmit malware, malicious code, viruses, spyware, or harmful content;
- disrupt, overload, impair, damage, or interfere with the Services or related systems;
- attempt to gain unauthorized access to accounts, systems, data, models, APIs, networks, or infrastructure;
- bypass, disable, jailbreak, evade, or interfere with platform guardrails, safety systems, access controls, authentication, usage limits, or security features;
- scrape, harvest, extract, or collect data from the Services without authorization;
- impersonate others or misrepresent affiliation, identity, authorization, or consent;
- send spam, unlawful marketing, deceptive messages, harassment, or abusive communications;
- process restricted data without a required separate agreement;
- deploy high-risk or regulated AI systems without raia's prior written authorization;
- remove, alter, obscure, disable, strip, or interfere with any AI Transparency Feature;
- misrepresent an AI Agent as a human or conceal the person or entity on whose behalf the AI Agent acts;
- make an unauthorized change in Intended Purpose, rebrand an AI Agent in a manner that changes provider status, or make a Substantial Modification without required notice and approval;
- fail to provide a disclosure, notice, label, human oversight, or downstream marking required by Applicable AI Laws;
- use the Services for a practice prohibited by Article 5 of the EU AI Act or another Applicable AI Law;
- use the Services in a way that creates legal, security, operational, reputational, or abuse risk to raia, its customers, providers, or users.
15A. Prohibited AI Practices
Customer, Authorized Users, and Public Users may not use, configure, market, distribute, modify, or enable the Services or an AI Agent for any practice prohibited by Article 5 of the EU AI Act, as amended, or by another Applicable AI Law.
Without limiting that prohibition, prohibited uses include unlawful manipulation or exploitation; prohibited social scoring; prohibited prediction of criminal risk; prohibited untargeted facial-image scraping; prohibited biometric categorisation based on sensitive attributes; prohibited emotion inference in workplaces or educational institutions; prohibited real-time remote biometric identification in publicly accessible spaces; and the generation or manipulation of non-consensual intimate material or child sexual abuse material, in each case to the extent prohibited by Applicable AI Laws.
Customer must not circumvent, disable, or attempt to defeat a technical or organizational safeguard designed to prevent such content or practices. Customer must immediately stop the affected use and notify raia if Customer becomes aware of a prohibited output, reasonably reproducible prohibited outcome, safeguard circumvention, or misuse. raia may immediately block content, suspend an AI Agent or account, preserve relevant records, and take other remedial action reasonably necessary to comply with law, protect persons, or address misuse.
16. Suspension, Restriction, and Remedial Actions
raia may suspend, restrict, throttle, disable, block, remove, modify, or terminate access to any account, AI Agent, workflow, integration, content, message, feature, API, model, or Service if raia determines that activity may:
- violate these Terms or applicable law;
- create security, privacy, legal, compliance, spam, abuse, fraud, platform, provider, or reputational risk;
- generate excessive spam complaints, abuse reports, or provider complaints;
- threaten platform stability, availability, security, or integrity;
- violate third-party provider terms or policies;
- expose raia, Customer, Public Users, or third parties to liability;
- involve unpaid amounts or payment failure;
- involve an undisclosed EU Deployment, a prohibited AI practice, an unauthorized high-risk use, an unauthorized change in Intended Purpose or Substantial Modification, a serious AI incident, removal or circumvention of an AI Transparency Feature, or failure to provide information or cooperation reasonably requested for compliance with Applicable AI Laws;
- require suspension, modification, preservation of records, notification, corrective action, or withdrawal from the market under Applicable AI Laws;
- otherwise create risk to the Services.
raia may take immediate action without prior notice where it determines that immediate action is necessary or appropriate.
17. Usage Limits and Fair Use
raia may apply usage limits, rate limits, message limits, API limits, AI model limits, workflow limits, storage limits, concurrency limits, or other fair-use restrictions.
Usage limits may vary by subscription plan, product, model, provider, feature, or written agreement.
raia may throttle, restrict, suspend, or require plan changes where usage exceeds applicable limits or creates service, cost, provider, abuse, or stability concerns.
18. Fees, Payment, Taxes, and Renewal
Customer must pay all fees stated in the applicable subscription, order form, checkout page, invoice, or written agreement.
raia accepts payment by Stripe, ACH, wire transfer, or check, as approved by raia.
Unless otherwise stated in a written agreement, subscriptions automatically renew until cancelled. Customer may cancel anytime before renewal.
Fees are non-refundable except where required by law or expressly stated in a separate written agreement or order form.
Taxes are not included in listed fees unless expressly stated. Customer is responsible for all applicable taxes, duties, levies, and governmental charges, except taxes based on raia's net income.
If Customer fails to pay amounts when due, raia may suspend or terminate access to the Services.
Termination or cancellation does not relieve Customer of payment obligations incurred before termination or cancellation.
19. Free Trials, Beta Features, and Unpaid Access
raia may offer free trials, beta features, preview features, pilot programs, experimental tools, unpaid access, or evaluation access.
Free trials, beta features, preview features, and unpaid access are provided "as is," without warranties, uptime commitments, support commitments, service-level commitments, or availability guarantees.
raia may modify, limit, suspend, or discontinue free, beta, preview, pilot, or unpaid features at any time.
Unless a separate written agreement states otherwise, beta/free/unpaid access is excluded from uptime, support, warranty, and service-level commitments.
20. Support and Service Levels
raia provides support through its standard support channels. Support levels, response times, availability, and service commitments may vary by subscription plan or separate written agreement.
Uptime commitments, service-level agreements, service credits, dedicated support, or other support commitments apply only if expressly stated in a separate written agreement or order form.
21. Data Export and Post-Termination Access
Customer may export or download Customer Data during the subscription term using available product functionality.
Following termination, Customer may export available Customer Data during the 30-day post-termination retention period unless a separate written agreement states otherwise.
After the 30-day post-termination retention/export period, raia may delete Customer Data unless a separate written agreement requires a different retention period.
22. Term and Termination
These Terms remain in effect while Customer, Authorized Users, or Public Users access or use the Services.
Either party may terminate for material breach if the breach is not cured within 30 days after written notice.
raia may suspend access immediately for security, legal, abuse, payment, platform, provider, or reputational risks, as described in these Terms.
Upon termination, Customer must stop using the Services, and raia may disable access to accounts, AI Agents, workflows, integrations, APIs, and Customer Data, subject to any post-termination export period or separate written agreement.
Sections that by their nature should survive termination will survive, including payment obligations, ownership, confidentiality, disclaimers, limitations of liability, indemnification, dispute resolution, governing law, and any other provisions intended to survive.
Sections concerning Customer Data rights and responsibility, Customer representations and warranties, Data Claims, disclaimers, limitations of liability, indemnification, cooperation, evidence preservation, and payment or reimbursement obligations survive termination or expiration for so long as Customer-Sourced Data remains in the Services or a claim may lawfully be asserted.
23. Confidentiality
Each party may receive non-public business, technical, financial, product, security, customer, contractual, or operational information from the other party that is marked confidential or should reasonably be understood to be confidential.
Each party will use the other party's confidential information only to perform under these Terms or the applicable agreement and will protect it using reasonable care.
Confidentiality obligations do not apply to information that is publicly available without breach, already known without restriction, independently developed without use of confidential information, or lawfully received from a third party without confidentiality obligations.
Confidentiality obligations survive for 2 years after termination. Trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
24. Publicity
raia may not use Customer's name, logo, trademarks, or branding in customer lists, websites, sales materials, press releases, or case studies without Customer's prior written approval.
25. Disclaimers
Except as expressly provided in a fully executed written agreement between raia and Customer, the Services are provided "as is" and "as available."
raia disclaims all warranties, express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, uninterrupted operation, error-free operation, availability, security, or reliability.
raia does not warrant that the Services, AI Agents, AI outputs, integrations, messages, workflows, APIs, models, or third-party services will be accurate, complete, lawful, secure, uninterrupted, timely, error-free, or suitable for Customer's intended use.
Customer is solely responsible for evaluating, testing, validating, approving, monitoring, and supervising its use of the Services and AI Agents.
CUSTOMER DATA DISCLAIMER. TO THE FULLEST EXTENT PERMITTED BY LAW, RAIA MAKES NO REPRESENTATION OR WARRANTY CONCERNING CUSTOMER-SOURCED DATA OR IMPORTED DATA, INCLUDING ITS CONTENT, SOURCE, PROVENANCE, OWNERSHIP, LICENSING, ACCURACY, COMPLETENESS, QUALITY, INTEGRITY, LEGALITY, NON-INFRINGEMENT, CONFIDENTIALITY, PRIVACY STATUS, SECURITY CLASSIFICATION, OR SUITABILITY FOR PROCESSING. RAIA DOES NOT WARRANT THAT CUSTOMER HAS THE RIGHTS, PERMISSIONS, CONSENTS, NOTICES, AUTHORIZATIONS, OR LAWFUL BASES REQUIRED TO MAKE ANY DATA AVAILABLE TO THE SERVICES.
RAIA'S TECHNICAL ABILITY TO RECEIVE, ACCESS, CONNECT TO, SYNCHRONIZE, IMPORT, STORE, OR PROCESS CUSTOMER-SOURCED DATA DOES NOT CONSTITUTE APPROVAL, ENDORSEMENT, CLEARANCE, VERIFICATION, OR A DETERMINATION THAT THE DATA OR PROCESSING IS LAWFUL.
26. Limitation of Liability
Unless otherwise expressly agreed in a fully executed written agreement, to the fullest extent permitted by law, raia will not be liable for indirect, incidental, special, consequential, exemplary, punitive, or enhanced damages, including lost profits, lost revenue, lost business, loss of goodwill, loss of data, loss of use, business interruption, or replacement services, whether arising in contract, tort, strict liability, negligence, warranty, or otherwise.
Unless otherwise expressly agreed in a fully executed written agreement, raia's total aggregate liability for all claims arising out of or relating to these Terms or the Services will not exceed the total amounts actually paid by Customer to raia during the one month immediately preceding the event giving rise to liability.
Without limiting the foregoing, and to the fullest extent permitted by law, raia will have no liability arising out of or relating to Customer-Sourced Data or a Data Claim, including any allegation that Customer-Sourced Data was unlawfully collected, disclosed, uploaded, imported, synchronized, processed, used, retained, or deleted; infringes or misappropriates intellectual property, confidentiality, privacy, publicity, contractual, proprietary, or other rights; contains Personal Data or Restricted Data; or was made available without adequate ownership, license, permission, notice, consent, authorization, approval, or lawful basis. This exclusion applies under any theory of liability and regardless of whether the claim is asserted by Customer, an Authorized User, a Public User, a data subject, a rights holder, a third-party application provider, or another person.
If the foregoing exclusion is held inapplicable to any claim, all other exclusions and the aggregate liability cap in this Section apply to that claim to the maximum extent permitted by law. The limitations in this Section apply collectively to raia and its affiliates, officers, directors, employees, contractors, subprocessors, providers, licensors, and agents and will not be enlarged by multiple claims, claimants, events, accounts, AI Agents, integrations, or legal theories.
Nothing in these Terms limits liability that cannot legally be limited.
Customer agrees that the limitations in this section are reasonable and form an essential basis of the bargain between Customer and raia.
27. Indemnification
27.1 Customer indemnity
Customer will defend, indemnify, and hold harmless raia, its affiliates, officers, directors, employees, contractors, subprocessors, providers, licensors, and agents (collectively, the "raia Indemnified Parties") from and against all claims, demands, actions, complaints, investigations, inquiries, subpoenas, proceedings, allegations, takedown requests, damages, judgments, settlements, losses, liabilities, penalties, fines to the extent legally indemnifiable, assessments, costs, and expenses, including reasonable attorneys' fees, expert fees, forensic costs, notification costs, remediation costs, and costs of responding to a regulator or rights holder, arising out of or relating to:
- (a) Customer-Sourced Data or any Data Claim;
- (b) Customer's or an Authorized User's collection, acquisition, access, copying, disclosure, submission, upload, connection, synchronization, import, processing, use, sharing, retention, deletion, or other handling of Customer-Sourced Data;
- (c) any allegation that Customer-Sourced Data infringes, misappropriates, or violates a copyright, patent, trademark, trade secret, database right, moral right, privacy right, publicity right, confidentiality obligation, proprietary right, contract, license, third-party application term, or other right;
- (d) Customer's actual or alleged failure to own or obtain any necessary right, license, permission, notice, consent, authorization, approval, or lawful basis concerning Customer-Sourced Data;
- (e) Customer's processing of Personal Data or Restricted Data, including failure to provide required notices, honor applicable rights, establish a lawful basis, execute a required written agreement, or comply with privacy, data-protection, security, breach-notification, records, employment, communications, consumer-protection, sector-specific, or other applicable requirements;
- (f) Imported Data or Customer's use, selection, configuration, permissions, credentials, access scope, or instructions concerning a third-party application, API, MCP tool, connector, integration, account, workflow, database, automation, or AI Agent;
- (g) Customer's AI Agents, prompts, instructions, configurations, workflows, messages, outputs, actions, decisions, recipients, deployments, monitoring, or Public User interactions;
- (h) Customer's breach of these Terms, an applicable written agreement, or applicable law;
- (i) misuse of the Services by Customer, an Authorized User, a Public User interacting with Customer's AI Agent, or any person or system using Customer's accounts, credentials, permissions, agents, integrations, workflows, or connected systems;
- (j) Customer's inaccurate, incomplete, misleading, or untimely information regarding EU Deployment, Intended Purpose, deployment context, regulated features, affected persons, rebranding, modifications, or use of an AI Agent;
- (k) Customer's removal, alteration, circumvention, suppression, or failure to display or preserve an AI Transparency Feature;
- (l) Customer's failure to make a disclosure or apply a label required of Customer as a deployer or other operator under Applicable AI Laws;
- (m) Customer's prohibited AI practice, unauthorized high-risk or regulated use, unauthorized Substantial Modification, or change in Intended Purpose; or
- (n) Customer's failure to fulfill obligations that apply to Customer because Customer is or becomes a provider, deployer, importer, distributor, product manufacturer, or other operator under Applicable AI Laws.
Customer's defense obligation applies upon tender of a claim or demand and does not require a final finding that Customer violated law or a third party's rights. The indemnity applies to claims alleging joint, concurrent, secondary, contributory, or vicarious liability against a raia Indemnified Party to the extent the claim arises out of a matter described above, except to the extent indemnification is prohibited by applicable law.
Customer is not required to indemnify raia to the extent a claim, fine, or loss is finally determined to have resulted from raia's independent violation of a non-waivable legal obligation and not from Customer's conduct, breach, information, configuration, deployment, modification, or use.
27.2 Procedure
raia will provide reasonably prompt notice of an indemnified claim, provided that delayed notice relieves Customer of its obligations only to the extent Customer is materially prejudiced by the delay. Customer must use counsel reasonably acceptable to raia, diligently conduct the defense, keep raia informed, and obtain raia's prior written consent before settling any claim in a manner that admits fault by, imposes obligations on, restricts, or does not fully release a raia Indemnified Party.
raia may participate in the defense with counsel of its choice at its own expense. If Customer fails to assume or diligently conduct the defense, or if raia reasonably determines that a conflict of interest or material risk to a raia Indemnified Party exists, raia may assume control of the defense at Customer's expense. Customer will provide all cooperation and records reasonably requested, including evidence concerning data provenance, ownership, licenses, permissions, consents, notices, lawful bases, source systems, access scopes, credentials, configurations, prompts, workflows, logs, messages, recipients, and integrations.
27.3 No contractual cap on Customer indemnity
Customer's obligations under this Section are independent of, and are not subject to, any exclusion or limitation of Customer liability elsewhere in these Terms unless a fully executed written agreement expressly states that it limits Customer's obligations under this Section.
28. Export Controls and Sanctions
Customer may not access or use the Services in violation of U.S. export control laws, sanctions laws, or other applicable trade restrictions.
Customer may not use the Services in or for the benefit of prohibited countries, restricted parties, sanctioned entities, or restricted end uses.
Customer represents that it is not located in, organized under the laws of, or ordinarily resident in a sanctioned country and is not listed on any restricted-party list.
29. Force Majeure
Neither party will be liable for delay or failure to perform due to events beyond reasonable control, including natural disasters, war, terrorism, civil unrest, labor disputes, government action, internet failures, utility failures, provider outages, cloud-service outages, cyber incidents, denial-of-service attacks, pandemics, or other events beyond reasonable control.
This section does not excuse Customer's obligation to pay amounts due.
30. Notices
raia may provide notices by email to the account owner or administrator email address, by posting to docs.raiaai.com, or by other reasonable means.
Customer is responsible for keeping account and billing contact information current.
Notices to raia must be sent to:
- Raia LLC
- 1751 Mound Street
- Sarasota, FL 34236
- Email: r+privacy@raiaai.com
Security notices may be sent to: r+security@raiaai.com
31. Changes to These Terms
raia may update these Terms from time to time.
Updated Terms become effective when posted to docs.raiaai.com or otherwise made available, unless the updated Terms state a later effective date.
Continued use of the Services after the effective date of updated Terms constitutes acceptance of the updated Terms.
For new Customers, the Terms require affirmative acceptance through an unchecked clickwrap presented next to a conspicuous link to the complete Terms. For existing Customers, material risk-allocation changes may be presented to an authorized Customer administrator for affirmative acceptance before continued platform use, and raia will preserve the complete assent record.
32. Assignment
raia may assign or transfer its rights and obligations under these Terms without Customer consent.
Customer may not assign or transfer its rights or obligations under these Terms without raia's prior written consent, except in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets, provided the assignee agrees to be bound by these Terms and is not a competitor or prohibited party.
Any unauthorized assignment is void.
33. Dispute Resolution and Arbitration
33.1 Mandatory Arbitration
Any dispute, claim, or controversy arising out of or relating to these Terms, the Services, Customer Data, AI Agents, billing, access, APIs, outputs, communications, integrations, or the relationship between Customer and raia will be resolved by final and binding arbitration before a single qualified arbitrator under the rules of JAMS or the American Arbitration Association.
Both parties waive the right to a jury trial.
33.2 Arbitration Opt-Out
Customer may opt out of arbitration within 30 days after first accepting these Terms by sending written notice to:
- Raia LLC – Arbitration Opt-Out
- 1751 Mound Street
- Sarasota, FL 34236
- Email: r+privacy@raiaai.com
33.3 Covered Claims
Covered claims include, without limitation, billing disputes, access issues, account disputes, API failures, Customer Data disputes, AI-output disputes, intellectual property claims, privacy or data disputes, communications disputes, contract claims, tort claims, and statutory claims, except for the exceptions listed below.
33.4 Exceptions
The following disputes are not required to be arbitrated:
- individual claims filed in small claims court;
- government enforcement actions;
- claims seeking injunctive relief for intellectual property infringement or unauthorized access;
- disputes about the enforceability of this arbitration clause.
33.5 Class Action Waiver
All claims must be brought individually. Customer and raia waive any right to participate in a class action, collective action, consolidated action, private attorney general action, or representative proceeding.
33.6 Governing Arbitration Law and Forum
This arbitration agreement is governed by the Federal Arbitration Act and, where not inconsistent, Florida law.
Unless otherwise required by applicable arbitration rules or law, arbitration will take place in Sarasota, Florida. Customer consents to arbitration in Sarasota, Florida and waives defenses based on lack of personal jurisdiction, venue, or inconvenient forum.
33.7 Arbitration Fees
Arbitration fees will be allocated according to the applicable JAMS or AAA rules.
33.8 Confidentiality
The parties agree to keep arbitration proceedings, submissions, evidence, and awards confidential except as required by law, to enforce an award, or to seek judicial relief permitted under these Terms.
34. Governing Law and Jurisdiction
These Terms are governed by the laws of the State of Florida, without regard to conflict-of-law principles.
Any non-arbitrable dispute will be brought exclusively in the state or federal courts located in Sarasota County, Florida. Customer consents to personal jurisdiction and venue in those courts and waives defenses based on lack of personal jurisdiction, venue, or inconvenient forum.
35. Severability
If any provision of these Terms is held invalid, illegal, or unenforceable, the remaining provisions will remain in full force and effect.
36. Entire Agreement
These Terms, together with the Privacy Policy and any applicable written agreement, order form, Data Processing Addendum, Business Associate Agreement, or other written terms between Customer and raia, constitute the entire agreement between the parties regarding the Services and supersede all prior or contemporaneous agreements regarding the same subject matter.
37. Contact
For questions about these Terms, contact:
- Raia LLC
- 1751 Mound Street
- Sarasota, FL 34236
- Email: r+privacy@raiaai.com
EU Data Residency & Support for European Customers
Raia supports customers across the European Union, United Kingdom and European Economic Area. Where the underlying service provider offers regional deployment or EU data residency, raia can configure production environments to keep customer data in EU-based infrastructure. The data-residency options available to a particular customer depend on the specific subscription, integration, deployment model and service configuration.
| Service / component | EU data-residency support | Security documentation |
|---|---|---|
| raia CX | EU deployment supported for customer-facing CX workloads. | Trust Center |
| raia Command | Backend control-plane data can be hosted in EU regions. | Trust Center |
| Google Cloud | EU regions available. | Security & Compliance |
| Supabase | EU database regions available. | Security |
| OpenAI | EU data-residency options available for eligible API usage. | Security |
| OpenRouter | EU data handling per provider trust documentation. | Trust Center |
| n8n | EU-hosted and self-hosted workflow options available. | Security |
| Twilio | EU data-residency options available for eligible services. | Security |
| Mailgun | EU region available. | Security |
Shared responsibility: Data residency and regional configuration depend on the specific services, subscription tier and customer setup. Customers should confirm their requirements with raia during onboarding and review each subprocessor's current security documentation.
European Regulatory Readiness
Raia supports customers evaluating artificial-intelligence and ICT service providers under European regulatory requirements. Our program combines independently assessed security controls with customer-specific contracting, transparency, risk assessment and operational cooperation.
This page is maintained by raia to describe our current regulatory-readiness program. It is not a certification, legal advice, or a substitute for a customer's own regulatory assessment. Each customer remains responsible for its own compliance obligations.
On this topic
Request Regulatory Assurance Information
Qualified customers may contact r+security@raiaai.com to request Raia's applicable SOC 2 Type II report, discuss a DORA assessment, request a scoped security, resilience or provider review, or discuss an EU AI Act role, transparency or regulated-use assessment.
Shared responsibility: Each customer remains responsible for determining its own regulatory obligations, classifying its use of Raia, configuring and operating its deployment appropriately, maintaining required records, providing applicable notices, performing required human oversight and obtaining its own legal advice.
Regulatory references: Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2026/1744 (Digital Omnibus amendments to the AI Act).
Digital Operational Resilience Act (DORA)
The EU Digital Operational Resilience Act, or DORA, directly establishes requirements for regulated financial entities. DORA is not a general certification for software vendors, and using Raia does not transfer a customer's regulatory responsibilities. Raia provides information, assurance and cooperation to help applicable customers assess and manage Raia as an ICT third-party service provider.
Security and resilience foundation
Raia's DORA customer-enablement work builds on its SOC 2 Type II examination and documented controls for information security, identity and access management, encryption, logging and monitoring, change management, vulnerability management, incident response, vendor risk, backup, business continuity and disaster recovery.
SOC 2 and DORA serve different purposes. Raia's SOC 2 Type II report provides independent assurance about the controls within the report's defined system, scope and examination period. DORA additionally requires regulated customers to address matters such as ICT contract terms, provider and location data, incident-reporting support, ongoing monitoring, resilience testing, audit and authority access, subcontracting and exit planning.
Support for financial-services assessments
| Review area | Raia support |
|---|---|
| Independent assurance | Qualified customers may request Raia's applicable SOC 2 Type II report and supporting security documentation under appropriate confidentiality terms. |
| Security documentation | Raia maintains documented policies and procedures for security, access, encryption, vulnerability management, incident response, business continuity, disaster recovery, vendor management and data protection. |
| Incident cooperation | Raia maintains processes for detection, escalation, containment, recovery, evidence preservation, customer communication and post-incident review. Applicable notice and cooperation commitments are governed by the customer agreement. |
| Operational resilience | Raia maintains backup, business-continuity and disaster-recovery procedures and conducts recurring exercises. Additional architecture, recovery-objective and test information may be made available to qualified customers under confidentiality terms. |
| Provider information | Raia performs risk-based reviews of relevant providers and can discuss service, processing-location and provider information for a scoped assessment. |
| Data return | Raia supports customer-data export, retention and deletion in accordance with the applicable agreement, product capabilities and data-protection terms. |
| Customer-specific review | Raia's Security and Legal teams can review DORA due-diligence requests and proposed contractual requirements for the customer's intended service and deployment. |
DORA customer-enablement program
Raia is extending its existing SOC 2 control program with DORA-oriented customer deliverables, including contractual terms, structured provider and location information, incident-reporting support, resilience and testing evidence, audit cooperation, relevant subcontractor information, and exit and transition documentation.
The requirements applicable to a particular arrangement depend on the Raia services used, the customer's regulated activities, the deployment and data involved, and whether the customer classifies the supported function as critical or important.
EU Artificial Intelligence Act
The EU AI Act assigns obligations according to the AI system, its intended purpose, the parties' roles and the deployment context. It is not a single company-level certification. Raia therefore assesses compliance at both the platform level and, when appropriate, for a specific AI system or authorized regulated deployment.
Current AI governance approach
Raia's agreements restrict unapproved high-risk and regulated AI uses, require customers to review and validate AI-generated outputs, and assign customers responsibility for the agents, data, workflows, integrations, notices, permissions and connected actions they control. Uses involving legally significant decisions or specified regulated data require additional review and, where applicable, Raia's prior written authorization.
Raia is implementing and documenting an EU AI Act readiness program that includes:
| Program area | Raia approach |
|---|---|
| AI system inventory | Identifying Raia-provided systems, upstream model dependencies, intended purposes, owners, data categories, deployment channels and prohibited or restricted uses. |
| Role and risk classification | Assessing whether Raia, a customer, a reseller or an upstream provider acts as provider, deployer or another operator for the specific system and use. |
| AI transparency | Supporting clear disclosure when a person interacts with a Raia-powered AI system and evaluating applicable marking or disclosure requirements for synthetic content. |
| Human review | Requiring appropriate review and authorization before AI output is used for a legally significant or regulated decision. |
| AI literacy | Providing role-appropriate guidance and training for personnel who develop, operate, support, sell or govern AI systems. |
| Provider governance | Evaluating relevant upstream AI and technology providers through Raia's vendor-management and security processes. |
| Regulated-use approval | Requiring a separate assessment and written authorization before the Platform is used for a proposed high-risk or regulated AI use. |
| Monitoring and response | Extending security, incident, complaint and corrective-action processes to address AI-specific safety, misuse and compliance events. |
Authorized regulated uses
A customer proposing an authorized regulated or potentially high-risk use should provide sufficient information for Raia to assess the intended purpose, users, affected persons, data, outputs, decision impact, human oversight, modifications and deployment context. Where required, Raia and the customer will document applicable roles and responsibilities in a written order form or compliance schedule.
Raia does not develop or market the underlying general-purpose AI models supplied by third-party model providers merely by integrating those models into the Platform. Raia remains responsible for obligations that apply to the AI systems and components it provides, while customers remain responsible for the deployment choices, data, workflows and decisions under their control, subject in each case to mandatory law.