EU data residency
Customer application data and working documents are processed and stored in the EU: all application services, databases, and document storage run in Google Cloud's Frankfurt region (europe-west3), with backups in the EU.
Regulatory teams get sold a lot of theatre. Here is exactly where your data lives, what the AI is allowed to do, and what we record — in plain language first, then the detail your DPO will ask for.
Customer application data and working documents are processed and stored in the EU: all application services, databases, and document storage run in Google Cloud's Frankfurt region (europe-west3), with backups in the EU.
All LLM and embedding calls use Vertex AI pinned to the Frankfurt region, authenticated by IAM roles — no API keys. Under Google Cloud's Vertex AI terms, your data is not used to train models.
Compliance-relevant actions — sign-offs, exports, guidance acknowledgments, failed logins, permission denials — are written to an append-only audit log designed against ALCOA+ principles and GAMP 5 expectations.
Every tenant's data is isolated at the API layer (default-deny permissions), the query layer, and the database itself (PostgreSQL row-level security). One layer failing does not expose data.
Regulation source documents are fetched with recorded checksums and verified before they enter the knowledge graph. Technical-file exports are anchored by an append-only SHA-256 snapshot manifest.
The knowledge graph decides what applies; the LLM only suggests, and every suggestion waits for human approval. LLMs never autonomously determine compliance — that rule is architectural, not a policy promise.
The details a data protection officer will want, stated plainly:
RunaReg does not make regulatory determinations. It references regulation text, flags issues, and records decisions — the qualified consultant or manufacturer decides.
RunaReg does not submit to EUDAMED and is not an eQMS. It prepares documentation and readiness before those systems take over.
Nothing is labeled "verified by RunaReg". Verification language belongs to Notified Bodies and competent authorities, not to software.