Trust Center

Security and trust at Rescana

We help security teams assess the risk of their vendors at scale. We hold ourselves to that same standard. This page summarizes our security, privacy, compliance, and AI governance posture — and how to request our documentation.

Request documentation →
SOC 2 Type II
Independent audit of our security, availability, and confidentiality controls.
Report available
ISO 27001
Certified information security management system.
Certified
ISO 27018
Certified protection of personal data in the cloud.
Certified
GDPR
Compliant data handling with a DPA available on request.
Compliant

Data security

Defense-in-depth controls protect customer data across its lifecycle.

Encryption

  • All data encrypted in transit with TLS
  • Data at rest encrypted with AES-256
  • Encrypted, regularly tested database backups

Access control

  • Least-privilege, need-to-know access
  • Permissions reviewed quarterly
  • Access revoked immediately on offboarding

Infrastructure

  • Hosted on hardened cloud infrastructure
  • Firewalls, antivirus, and network segmentation
  • Logical tenant isolation between customers

Resilience

  • Encrypted backups with regular restore tests
  • Monitoring and alerting on the production environment
  • Documented incident response process

AI & agent governance

Rescana runs autonomous AI agents on your behalf, against our models or yours. We design those agents to be transparent, bounded, and safe with your data.

Bring your own model

Run Rescana against a model endpoint you designate, including one in your own cloud tenancy or under your own agreement with a provider. Your content goes there instead of to our default providers, that provider is not our sub-processor, and its processing, retention and training terms are the ones you have already negotiated.

Your data is not used to train models

We never use customer data to train models. Where we provide the model, our agreements with those providers prohibit your content being used to train their foundation models. Where you bring your own model, those terms are yours to set.

Bounded autonomy

Agents operate within defined guardrails and scopes. Sensitive or high-impact actions are designed to keep a human in the loop.

Transparent data flows

Where we provide the model, the LLM providers we rely on are named in our sub-processor list, so you always know where data is processed. Where you bring your own, you choose the destination.

Acceptable use

Use of our AI features is governed by our AI Terms, which set out responsible-use expectations.

Privacy & data protection

Rescana Ltd. is the data controller for our site and the processor for customer data we handle on your behalf.

Your rights

  • Access, correction, portability, and deletion
  • Restriction of and objection to processing
  • Defined data retention and deletion policy

Documents

International transfers

Cross-border transfers rely on adequacy decisions or EU Standard Contractual Clauses to maintain EEA-equivalent protection.

Sub-processors

When acting as a processor for our customers, Rescana engages the sub-processors below. The AI providers listed apply where Rescana provides the model — if you designate your own model endpoint, that provider is not our sub-processor. This list may be updated from time to time; contact us to subscribe to change notifications.

Sub-processorPurposeLocation
OpenAINatural language processingUSA
AWSCloud computing and storageUSA / Global
MixpanelProduct analyticsUSA
SegmentCustomer data infrastructureUSA
HubSpotCRMUSA
SendGridEmail deliveryUSA
SlackSecure messagingUSA
Have I Been PwnedData breach intelligenceAustralia

Vulnerability disclosure

We welcome reports from the security community. If you believe you have found a vulnerability in Rescana, please tell us.

How to report

Email security@rescana.com with details and reproduction steps. We acknowledge reports and work with you in good faith toward a resolution. Please do not publicly disclose before we have remediated.

Testing pledge

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to respond.

Request our security documentation

Our SOC 2 Type II report, ISO certificates, penetration test summary, DPA, and completed security questionnaires (SIG / CAIQ) are available to customers and prospects under NDA.

Request access →

Prefer to talk to a person? Contact our team or email legal@rescana.com.

This Trust Center is reviewed regularly. For specific questions, contact security@rescana.com.