RheXa processes real customer conversations. That means security, privacy, and compliance are non-negotiable. Here is exactly how we protect your data and your customers' data.
GDPR Compliant
TLS 1.3 Encrypted
AES-256 At Rest
SOC 2 In Progress
2FA On All Accounts
No AI Training On Your Data
Encryption everywhere
All data encrypted in transit via TLS 1.3
All data encrypted at rest via AES-256
Database connections encrypted end-to-end
API keys and secrets stored in encrypted vaults
Data isolation
Multi-tenant architecture with strict org_id isolation
No cross-tenant data access — ever
Supabase Row Level Security on every table
Dedicated database schemas per organization
Access control
Two-factor authentication on all accounts
Role-based permissions — Owner, Admin, Member
Session tokens expire after 24 hours of inactivity
All login attempts logged and anomalies flagged
Compliance
GDPR compliant from day one
SOC 2 Type II in progress (estimated Q4 2026)
UK GDPR and EU GDPR covered
Privacy-by-design architecture — minimal data collection
AI safety
Customer data never used to train AI models
Confidence scoring prevents hallucinated replies
Legal and sensitive messages always escalated — never auto-replied
All AI activity logged with full audit trail
Your data, your control
Delete all your data at any time — permanently
Data export available in JSON format on request
No data sold or shared with third parties
Clear data retention policy — 12 months post-cancellation
Responsible AI
We don't train on your data
Your conversations, knowledge base, and customer data are never used to improve any AI model — ours or our providers'. Your business context stays private. Always.
The AI knows when to stop
Every reply includes a confidence score. If the AI isn't sure, it holds the message and notifies you. Legal threats, complaints, and sensitive messages are always escalated to a human — no exceptions.
Full audit trail
Every AI action is logged with a timestamp, the message content, the confidence score, and the outcome. You can review, export, or delete any part of this log at any time.
Security Disclosure
If you discover a security vulnerability, please report it responsibly to rhexorg@gmail.com. We aim to respond within 48 hours and will work with you to resolve the issue quickly. We do not pursue legal action against responsible disclosures.
Security questions?
Our team is happy to walk enterprise customers through our full security posture.