Trust & Security

Everything on this page is verifiable. That's the point.

Regulatory teams get sold a lot of theatre. Here is exactly where your data lives, what the AI is allowed to do, and what we record — in plain language first, then the detail your DPO will ask for.

EU data residency

Customer application data and working documents are processed and stored in the EU: all application services, databases, and document storage run in Google Cloud's Frankfurt region (europe-west3), with backups in the EU.

AI with no-training terms

All LLM and embedding calls use Vertex AI pinned to the Frankfurt region, authenticated by IAM roles — no API keys. Under Google Cloud's Vertex AI terms, your data is not used to train models.

ALCOA+ audit trail

Compliance-relevant actions — sign-offs, exports, guidance acknowledgments, failed logins, permission denials — are written to an append-only audit log designed against ALCOA+ principles and GAMP 5 expectations.

Tenant isolation, three layers

Every tenant's data is isolated at the API layer (default-deny permissions), the query layer, and the database itself (PostgreSQL row-level security). One layer failing does not expose data.

SHA-256 evidence provenance

Regulation source documents are fetched with recorded checksums and verified before they enter the knowledge graph. Technical-file exports are anchored by an append-only SHA-256 snapshot manifest.

Deterministic-first architecture

The knowledge graph decides what applies; the LLM only suggests, and every suggestion waits for human approval. LLMs never autonomously determine compliance — that rule is architectural, not a policy promise.

For your DPO

The details a data protection officer will want, stated plainly:

  • Roles: for platform customer data, the customer is the controller and RunaReg is the processor. For data submitted through this website's demo form, RunaReg is the controller.
  • Subprocessors: Google Cloud (hosting and AI, Frankfurt europe-west3), Resend (transactional email), Cloudflare (website hosting, CDN, bot protection, cookieless analytics).
  • Google support access is governed by Standard Contractual Clauses in line with GDPR Article 28 processor terms.
  • One honest caveat: Google Cloud's mandatory `_Required` audit-log tier is operated on Google's global logging infrastructure and cannot be regionalized by any customer. Customer application data and working documents stay in the EU regions above.
  • This website sets no tracking cookies. Analytics is Cloudflare Web Analytics — cookieless and aggregate. The demo form data flow is described in the privacy policy, including retention and erasure contact.
  • Data subject requests: hello@runareg.com.

What RunaReg deliberately does not do

RunaReg does not make regulatory determinations. It references regulation text, flags issues, and records decisions — the qualified consultant or manufacturer decides.

RunaReg does not submit to EUDAMED and is not an eQMS. It prepares documentation and readiness before those systems take over.

Nothing is labeled "verified by RunaReg". Verification language belongs to Notified Bodies and competent authorities, not to software.

This site currently uses no tracking cookies and no marketing pixels. Cloudflare Web Analytics is cookieless and aggregate. These settings exist so that if we ever add optional technologies, nothing loads without your opt-in.