RheXa
PricingUse CasesBlogDemo
Sign InGet Started
RheXa
PricingUse CasesBlogDemoAboutChangelogSecurity
Sign inGet Started
Security & Trust

Security is not a feature.
It's the foundation.

RheXa processes real customer conversations. That means security, privacy, and compliance are non-negotiable. Here is exactly how we protect your data and your customers' data.

GDPR Compliant
TLS 1.3 Encrypted
AES-256 At Rest
SOC 2 In Progress
2FA On All Accounts
No AI Training On Your Data

Encryption everywhere

  • All data encrypted in transit via TLS 1.3
  • All data encrypted at rest via AES-256
  • Database connections encrypted end-to-end
  • API keys and secrets stored in encrypted vaults

Data isolation

  • Multi-tenant architecture with strict org_id isolation
  • No cross-tenant data access — ever
  • Supabase Row Level Security on every table
  • Dedicated database schemas per organization

Access control

  • Two-factor authentication on all accounts
  • Role-based permissions — Owner, Admin, Member
  • Session tokens expire after 24 hours of inactivity
  • All login attempts logged and anomalies flagged

Compliance

  • GDPR compliant from day one
  • SOC 2 Type II in progress (estimated Q4 2026)
  • UK GDPR and EU GDPR covered
  • Privacy-by-design architecture — minimal data collection

AI safety

  • Customer data never used to train AI models
  • Confidence scoring prevents hallucinated replies
  • Legal and sensitive messages always escalated — never auto-replied
  • All AI activity logged with full audit trail

Your data, your control

  • Delete all your data at any time — permanently
  • Data export available in JSON format on request
  • No data sold or shared with third parties
  • Clear data retention policy — 12 months post-cancellation

Responsible AI

We don't train on your data

Your conversations, knowledge base, and customer data are never used to improve any AI model — ours or our providers'. Your business context stays private. Always.

The AI knows when to stop

Every reply includes a confidence score. If the AI isn't sure, it holds the message and notifies you. Legal threats, complaints, and sensitive messages are always escalated to a human — no exceptions.

Full audit trail

Every AI action is logged with a timestamp, the message content, the confidence score, and the outcome. You can review, export, or delete any part of this log at any time.

Security Disclosure

If you discover a security vulnerability, please report it responsibly to rhexorg@gmail.com. We aim to respond within 48 hours and will work with you to resolve the issue quickly. We do not pursue legal action against responsible disclosures.

Security questions?

Our team is happy to walk enterprise customers through our full security posture.

Talk to Sales rhexorg@gmail.com