Security & compliance
Trust isn't promised. It's audited.
Redijo is built to be verifiable: every figure traces back to its source, permissions hold the moment the answer is composed, and every answer leaves a hash-chained audit trail. GDPR-grade controls with international-transfer safeguards — governance you can prove, not just assert.
Infrastructure & data · governance
One converged region, encrypted. GDPR-grade controls.
Redijo's canonical files and database sit in a single converged cloud region, encrypted in transit and at rest. Privacy compliance comes from international-transfer safeguards and consent, backed by GDPR-grade controls — the sub-processor list, with each one's safeguards, ships with the DPA.
GDPR-grade controls
Encryption
Magic link
The permission & audit model
Permissions at synthesis time. A chained audit trail.
Most tools check access only when they fetch a document — then the AI blends everything into one answer. Redijo checks each fragment's permission at the moment the answer is written, and records it in a chained trail that can't be rewritten after the fact.
The folder is the access boundary
Each file lives in a folder, and the folder decides who can see what — for people and teams, inheriting downward with explicit overrides. Access belongs to the folder, not to scattered copies.
Per-fragment permission, at synthesis
When the agent writes an answer, permission is checked fragment by fragment, at synthesis time — not just at retrieval. Anything outside your access simply doesn't enter, not even hidden inside an aggregate number.
A hash-chained audit trail
Every answer records what was used, from where, by whom and when — in a hash-chained log where each entry seals the one before it. Rewriting history breaks the chain, and that's visible.
An honest posture
Auditable doesn't mean true. It means provable.
Redijo doesn't promise every figure is correct — it promises you can trace each one back to its source. That difference is what separates a tool you trust from a tool that proves, and it's the foundation of defensible governance.
- Auditable: every number points to the source file, sheet and row, verifiable in one click.
- When data is missing, Redijo flags the gap instead of inventing a number.
- The AI is never in the value path: calculation and comparison are deterministic; the AI drafts the prose around them.
Sub-processors
Who touches your data — and where.
We list the sub-processors Redijo uses to host and process data. Text recognition in images (OCR) uses Mistral, with no training on your data. The full, current list — with each one's safeguards — ships with the DPA.
| Sub-processor | Role | Commitment |
|---|---|---|
| Cloudflare R2 | Canonical file storage | Write-once, content-addressed |
| Neon | Database (queryable projection) | Rebuildable projection |
| Mistral | Document OCR (image → text) | No training on your data |
Sub-processors may change as the product evolves; we communicate changes, and the current list forms part of the DPA.
Documents
What you sign, in writing.
A DPA is available for businesses, with the international-transfer terms and the sub-processor list. The privacy policy and terms apply to everyone.
On the way
Certifications: on the roadmap, not on the badge.
Redijo is in pre-launch. We build the controls first and pursue the certifications next — and we only show a badge once it's been issued. Until then, we tell you exactly where we stand.
Redijo is not yet SOC 2 or ISO 27001 certified. We don't display badges we don't hold — when a certification is issued, it appears here with its date.
Frequently asked
Security, data and governance — no fine print.
Where is my company's data stored?
How does Redijo handle privacy and data-transfer compliance?
Is Redijo SOC 2 or ISO 27001 certified?
Who can see the data when the AI answers?
Can my own AI use Redijo with the same permissions?
Is my data used to train AI models?
Give your AI a memory you can audit.
Upload your first files in minutes. No card required.
DPA for businesses · SOC 2 on the roadmap · cancel anytime