Rakenne Trust Center
AI-powered document workflows for compliance and legal teams.
Rakenne is a multi-tenant SaaS platform that lets domain experts define document-elaboration workflows and collaborate with an LLM agent to produce structured, audit-ready output.
Welcome to Rakenne's Trust Center. We are actively building toward SOC 2 and ISO/IEC 27001 certification. Explore our security controls, compliance posture, resources, and subprocessor list below.
Compliance
Controls
Subprocessors
Resources
Security, compliance, privacy, and legal documentation for Rakenne.
Security Overview
Architecture, access control, encryption, monitoring, incident response, and shared responsibility model.
Compliance Roadmap
SOC 2 and ISO/IEC 27001 roadmap, current status, and how we use Rakenne to run our ISMS.
Privacy Overview
Personal data handling, AI processing, data location, retention, and data subject rights.
Legal Documents
DPA, Terms of Usage, Privacy Policy, and intellectual property commitments.
Data Processing Agreement
How Rakenne processes personal data as your processor under GDPR and applicable data protection laws.
Terms of Usage
Account eligibility, acceptable use, subscription and billing, service availability, and IP licensing.
IP Compliance
Content ownership, AI-generated output IP risk mitigation, and how we treat standards and regulatory texts.
Shared Responsibility Matrix
How security responsibilities are divided between Rakenne, our infrastructure providers, and you as the customer.
Controls
Security and compliance controls implemented across the Rakenne platform, adapted from SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A.
Subprocessors
Vendors we rely on to deliver the Rakenne platform. We minimize data shared with each provider and ensure appropriate data protection terms are in place.
Infrastructure & Hosting
Data encrypted in transit and at rest. Access restricted via IAM with least-privilege policies. SOC 2 and ISO 27001 certified.
AI Processing
Rakenne uses Google Gemini as the default LLM provider. Anthropic (Claude) and OpenAI are available only through Bring Your Own Key, where they act under your agreement.
Enterprise AI terms: customer data not used for training. Limited retention for operations and abuse prevention.
Email & Communications
Handles signups, verification, and app emails. Logs retained for a limited period for delivery and troubleshooting.
Used for human-operated support and contact inboxes. Separate from transactional email.
Billing & Subscription Management
Rakenne does not store full card numbers. Stripe retains data for tax and accounting obligations. PCI DSS compliant.
Analytics & Telemetry
Subject to consent where required. No document content or chat messages are sent to analytics.