Security
Your data. Your
perimeter.
Your keys.
RaptorX is deployed inside your environment. Data never leaves. Certified, auditable, documented — from day one.
01 · Certifications
Audited. Certified.
Documented.
SOC 2 Type II
Report available
under NDA.
Independently audited controls across security, availability, and confidentiality.
ISO 27001
Certified.
Continuously maintained.
Information security management aligned to international standard. Annual surveillance audits.
GDPR
Compliant.
DPA on request.
Data-processor addendum available. Sub-processor list documented. EU data residency supported.
02 · Deployment
Runs where
your data lives.
Choose the deployment that matches your data sovereignty, compliance, and infrastructure posture. Same platform. Same performance. Different perimeters.
Model 01
Managed Cloud
RaptorX-managed in AWS or Azure. Data-sovereign region of your choice. Fastest time to value.
Isolated Tenant · Region-Pinned
Model 02
Your VPC
Deployed inside your virtual private cloud. RaptorX operates the software; data stays in your AWS, Azure, or GCP account.
Your Account · Your Network
Model 03
On-premise
Air-gapped inside your data center. Full customer control. Zero outbound. For the most sensitive deployments.
Air-Gapped · Zero Outbound
Your data never leaves your
perimeter. Ever.
03 · Controls & Posture
The details
your CISO will ask for.
Data
Encryption at rest
AES-256
Encryption in transit
TLS 1.3
Key management
Your KMS / HSM
Secret storage
Vault / Secrets Manager
Data residency
Pinned to region
Backup encryption
Same as primary
Access & Audit
Access control
RBAC
Authentication
SSO / SAML
Audit logs
Every decision, immutable
Log retention
Configurable
Penetration testing
Annual, third-party
Vulnerability disclosure
04 · Contact & Documents
Full package,
on request.
Security Contact
Vulnerability disclosure, security questionnaires, audit packages, deployment architecture reviews.
Response SLA · 2 Business Days
Documents on Request
- SOC 2 Type II report
- ISO 27001 certificate
- Penetration test summary
- Data Processing Addendum (GDPR)
- CAIQ / SIG-Lite / VSA responses
- Architecture & deployment overview