Security & Compliance

Security Policy

Our comprehensive security practices protect your data with industry-leading encryption, compliance controls, and incident response procedures.

Read Full Policy
Last updated: 3 February 2026
SOC 2 Type IIGDPR99.9% Uptime
01

Data Encryption

All data is protected using industry-standard encryption at rest and in transit.

Raritone implements comprehensive encryption protocols to protect all customer data:

  • AES-256 encryption for all data at rest in storage systems
  • TLS 1.2+ for all data in transit between clients and servers
  • HMAC-SHA256 for data integrity verification
  • End-to-end encryption for voice data processing pipelines
  • Regular key rotation and management procedures

All encryption keys are securely stored and managed according to industry best practices.

02

Data Residency

Data is stored in secure, compliant cloud infrastructure with clear residency controls.

We maintain strict control over where your data is stored and processed:

  • Default data storage in AWS us-east-1 region
  • Regional data residency options available for enterprise customers
  • Automatic data replication for high availability within the same region
  • No cross-border data transfer without explicit customer consent
  • Compliance with regional data protection regulations

Enterprise customers can request alternative regions for data storage and processing.

03

Backup & Disaster Recovery

Comprehensive backup and recovery procedures ensure business continuity and data availability.

Raritone maintains rigorous backup and disaster recovery procedures:

  • Daily automated backups of all customer data
  • Recovery Time Objective (RTO): Less than 4 hours
  • Recovery Point Objective (RPO): Less than 1 hour
  • Off-region backup replication for disaster recovery
  • Regular backup restoration testing to ensure reliability
  • Immutable backup storage to prevent accidental deletion

Backups are retained for 30 days and automatically purged according to retention policies.

04

Access Controls

Strong authentication and authorization mechanisms control who can access customer data.

We implement multiple layers of access control to protect your data:

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication (MFA) for all admin and privileged accounts
  • API key rotation every 90 days for enhanced security
  • Principle of least privilege enforced across all systems
  • Session timeout after 30 minutes of inactivity
  • Comprehensive audit logging of all access attempts

All employees with data access undergo security training and background verification.

05

Incident Response

Defined procedures for detecting, responding to, and managing security incidents.

Our incident response process ensures rapid detection and mitigation of security issues:

Detection
Immediate
Automated monitoring detects anomalies
Containment
< 15 min
Affected systems are isolated to prevent spread
Investigation
< 2 hours
Security team investigates scope and impact
Notification
< 24 hours
Customers are notified with incident details
Resolution
Ongoing
Incident is resolved and preventive measures implemented
06

Compliance

Raritone maintains compliance with key security and privacy standards.

Our platform meets or exceeds major security and compliance frameworks:

SOC 2 Type II

Security, availability, and confidentiality controls certified

GDPR

Full compliance with EU General Data Protection Regulation

99.9% SLA

Uptime guarantee for production systems

AWS Security Best Practices

Aligned with AWS Well-Architected Framework

07

Contact & Support

Report security issues and get support through our dedicated security channels.

For security questions or to report vulnerabilities, contact our security team:

We respond to security inquiries within 24 hours.