Security & compliance

Trust isn't promised. It's audited.

Redijo is built to be verifiable: every figure traces back to its source, permissions hold the moment the answer is composed, and every answer leaves a hash-chained audit trail. GDPR-grade controls with international-transfer safeguards — governance you can prove, not just assert.

Infrastructure & data · governance

One converged region, encrypted. GDPR-grade controls.

Redijo's canonical files and database sit in a single converged cloud region, encrypted in transit and at rest. Privacy compliance comes from international-transfer safeguards and consent, backed by GDPR-grade controls — the sub-processor list, with each one's safeguards, ships with the DPA.

Single region

Files and database converged

GDPR-grade controls

Safeguards + DPA

Encryption

In transit and at rest

Magic link

Passwordless access

Cloudflare R2 · canonical filesNeon · managed databaseSingle converged regionGDPR-grade controlsInternational transfer with consent

The permission & audit model

Permissions at synthesis time. A chained audit trail.

Most tools check access only when they fetch a document — then the AI blends everything into one answer. Redijo checks each fragment's permission at the moment the answer is written, and records it in a chained trail that can't be rewritten after the fact.

01

The folder is the access boundary

Each file lives in a folder, and the folder decides who can see what — for people and teams, inheriting downward with explicit overrides. Access belongs to the folder, not to scattered copies.

02

Per-fragment permission, at synthesis

When the agent writes an answer, permission is checked fragment by fragment, at synthesis time — not just at retrieval. Anything outside your access simply doesn't enter, not even hidden inside an aggregate number.

03

A hash-chained audit trail

Every answer records what was used, from where, by whom and when — in a hash-chained log where each entry seals the one before it. Rewriting history breaks the chain, and that's visible.

An honest posture

Auditable doesn't mean true. It means provable.

Redijo doesn't promise every figure is correct — it promises you can trace each one back to its source. That difference is what separates a tool you trust from a tool that proves, and it's the foundation of defensible governance.

  • Auditable: every number points to the source file, sheet and row, verifiable in one click.
  • When data is missing, Redijo flags the gap instead of inventing a number.
  • The AI is never in the value path: calculation and comparison are deterministic; the AI drafts the prose around them.

Sub-processors

Who touches your data — and where.

We list the sub-processors Redijo uses to host and process data. Text recognition in images (OCR) uses Mistral, with no training on your data. The full, current list — with each one's safeguards — ships with the DPA.

Sub-processorRoleCommitment
Cloudflare R2Canonical file storageWrite-once, content-addressed
NeonDatabase (queryable projection)Rebuildable projection
MistralDocument OCR (image → text)No training on your data

Sub-processors may change as the product evolves; we communicate changes, and the current list forms part of the DPA.

Documents

A DPA is available for businesses, with the international-transfer terms and the sub-processor list. The privacy policy and terms apply to everyone.

On the way

Certifications: on the roadmap, not on the badge.

Redijo is in pre-launch. We build the controls first and pursue the certifications next — and we only show a badge once it's been issued. Until then, we tell you exactly where we stand.

SOC 2 Type IIOn the roadmap
ISO/IEC 27001On the roadmap
DPAAvailable for businesses

Redijo is not yet SOC 2 or ISO 27001 certified. We don't display badges we don't hold — when a certification is issued, it appears here with its date.

Frequently asked

Security, data and governance — no fine print.

Where is my company's data stored?
In a single converged cloud region under GDPR-grade controls: canonical files in write-once object storage (Cloudflare R2) and the database in Neon. The sub-processor list — who processes what, under which safeguards — ships with the DPA.
How does Redijo handle privacy and data-transfer compliance?
Privacy compliance comes from international-transfer safeguards and consent, backed by GDPR-grade controls. A DPA is available for businesses.
Is Redijo SOC 2 or ISO 27001 certified?
Not yet. Redijo is in pre-launch; those certifications are on the roadmap. We don't display badges we don't hold — when one is issued, it appears on this page with its date.
Who can see the data when the AI answers?
You only see what you're allowed to see. Permission is checked per fragment at synthesis time, and anything outside your access never enters the answer — not even inside an aggregate number.
Can my own AI use Redijo with the same permissions?
Yes. Redijo exposes a permission-aware MCP server with an audit trail, so bring your own assistant: synthesis stays on your side, under the same access rules.
Is my data used to train AI models?
No. Your data is not used to train models. Document OCR uses Mistral, also with no training on your data.

Give your AI a memory you can audit.

Upload your first files in minutes. No card required.

DPA for businesses · SOC 2 on the roadmap · cancel anytime