Security & compliance
Trust isn't promised. It's audited.
Redijo is built to be verifiable: every number points to its source, permissions hold at synthesis time, and every answer leaves a hash-chained audit trail. PDPA alignment comes from international-transfer safeguards and a DPA available for businesses.
Infrastructure & data · PDPA
One converged region, encrypted. PDPA-aligned by design.
Redijo's canonical files and database sit in a single converged cloud region, encrypted in transit and at rest. PDPA alignment comes from international-transfer safeguards and consent, with a DPA available for businesses — the sub-processor list, with each one's safeguards, ships with the DPA.
PDPA-aligned
Encryption
Magic link
The permission & audit model
Permissions at synthesis time. A chained audit trail.
Most tools check access only when they fetch a document — then the AI blends everything into one answer. Redijo checks each fragment's permission at the moment the answer is written, and records it in a chained trail that can't be rewritten after the fact.
The folder is the access boundary
Each file lives in a folder, and the folder decides who can see what — for people and teams, inheriting downward with explicit overrides. Access belongs to the folder, not to scattered copies.
Per-fragment permission, at synthesis
When the agent writes an answer, permission is checked fragment by fragment, at synthesis time — not just at retrieval. Anything outside your access simply doesn't enter, not even hidden inside an aggregate number.
A hash-chained audit trail
Every answer records what was used, from where, by whom and when — in a hash-chained log where each entry seals the one before it. Rewriting history breaks the chain, and that's visible.
An honest posture
Auditable doesn't mean true. It means verifiable.
Redijo doesn't promise every number is correct — it promises you can check each one back to its source. That difference is what separates a tool you trust from a tool that proves.
- Auditable: every number points to the source file, sheet and row, verifiable in one click.
- When data is missing, Redijo flags the gap instead of inventing a number.
- The AI is never in the value path: calculation and comparison are deterministic; the AI drafts the prose around them.
Sub-processors
Who touches your data — and where.
We list the sub-processors Redijo uses to host and process data. Text recognition in images (OCR) uses Mistral, with no training on your data. The full, current list — with each one's safeguards — ships with the DPA.
| Sub-processor | Role | Commitment |
|---|---|---|
| Cloudflare R2 | Canonical file storage | Write-once, content-addressed |
| Neon | Database (queryable projection) | Rebuildable projection |
| Mistral | Document OCR (image → text) | No training on your data |
Sub-processors may change as the product evolves; we communicate changes, and the current list forms part of the DPA.
Documents
What you sign, in writing.
A DPA is available for businesses, with the international-transfer terms and the sub-processor list. The privacy policy and terms apply to everyone.
On the way
Certifications: on the roadmap, not on the badge.
Redijo is in pre-launch. We build the controls first and pursue the certifications next — and we only show a badge once it's been issued. Until then, we tell you exactly where we stand.
Redijo is not yet SOC 2 or ISO 27001 certified. We don't display badges we don't hold — when a certification is issued, it appears here with its date.
Frequently asked
Security, data and audit — no fine print.
Where is my company's data stored?
Is Redijo aligned with Singapore's PDPA?
Is Redijo SOC 2 or ISO 27001 certified?
Who can see the data when the AI answers?
Can my own AI use Redijo with the same permissions?
Is my data used to train AI models?
Give your AI a memory you can audit.
Upload your first files in minutes. No card required.
PDPA-ready · DPA for businesses · cancel anytime