Security & privacy
Plant documentation is some of the most sensitive data you own. Raven keeps it inside your deployment boundary, processes it only to do the work you asked for, and never uses it to train AI models.
What touches your data
Your deployment boundary
AWS · Azure · GCP
Your plant documents
P&IDs · SOPs · datasheets · permits
Raven models run inside
P&ID vision + search · no external transfer
Third-party AI providers
LLM · embedding · OCR — ephemeral API call
Provider
Role
How your data is handled
Raven (proprietary)
Role
Fine-tuned vision models for P&IDs and engineering drawings; fine-tuned search agents for retrieval across plant documentation.
How your data is handled
Runs inside your deployment boundary. No external data transfer.
LLM providers
Role
Language reasoning and response generation.
How your data is handled
Ephemeral API call. Zero retention, zero training, no human review.
Embedding providers
Role
Embedding generation for semantic search.
How your data is handled
Ephemeral API call. Zero retention, zero training, no human review.
OCR / vision providers
Role
Text and layout extraction from documents and drawings.
How your data is handled
Ephemeral API call. Zero retention, zero training, no human review.
Every third-party AI provider is contractually bound
No training on your data, or on the results generated from it
No retention of your data beyond the immediate processing window
No human review of your data by provider personnel
Configurable to your security posture
Not every deployment uses every provider. The exact data path is reviewed and agreed with your team during enterprise evaluation, and provider use can be restricted where operationally feasible.
Security controls
Security Infrastructure
Raven's infrastructure is built with defense in depth. Protections include:
End-to-end encryption (TLS 1.2+ in transit, AES-256 at rest)
Least privilege access and identity management
Secure software development lifecycle with regular code review
Logical isolation of customer data per tenant
Operational Security
Raven continuously monitors the platform for threats. Controls include:
Incident response with defined severity levels and escalation
Intrusion prevention and automated alerting
Patch and vulnerability management with rapid remediation
Deployment & Access
Enterprises get fine-grained control over how Raven is deployed and who can use it:
Flexible deployment — Raven-managed, single-tenant, or your own cloud account
Role-based access control with SSO and full audit trails
Your data stays within your configured deployment boundary
SOC 2 Type II audit in progress; report available on completion
Privacy
Retention & Deletion
By default, Raven retains your data only for the duration of the engagement, and purges it from primary stores and backups after termination on the agreed timeline. You can define custom retention windows to match your own governance requirements.
Ownership & Rights
You retain full ownership of your data. We publish clear policies on how data is collected and processed, and honour access, rectification, and erasure requests — sent to security@startraven.com — after verifying identity and authority.
AI governance
Governance
Raven's AI features undergo legal, compliance, and technical review before launch, so AI use stays responsible and aligned with enterprise requirements.
Grounding & Traceability
Outputs are tied back to your source documents rather than presented as ungrounded model answers. Every response carries citations to the underlying documents and page references — so any answer can be checked against the record.
Human Review & Audit
Critical outputs run through review-and-correction loops before they count as validated, and user and system actions are logged for operational review. Improvement happens by re-ranking within your environment — never by training a model on your data.
Compliance & review
SOC 2 Type II — audit in progress
Raven is undergoing a SOC 2 Type II audit under the AICPA framework, evaluating the design and operating effectiveness of our security, availability, and confidentiality controls over time. The report will be made available to customers on completion.
Review it with your team
Your IT and security team can evaluate Raven before go-live — an architecture walkthrough, answers to your security questionnaire, and a deployment-specific data-flow review. Request the Security Welcome Packet from security@startraven.com.
Reliability
Enterprise-Grade Infrastructure
Raven runs on enterprise cloud infrastructure — AWS, Azure, or GCP — with deployment in your own cloud account where required. The deployment region is agreed with you and can accommodate specific data-residency requirements.
High Availability & Monitoring
Multi-zone redundancy and backup systems
Proactive monitoring with alerting on operational failures
Availability targets defined in your deployment SLA
Deployment Reviews
Pilot and rollout deployments go through a joint review with your IT and security team — architecture, access routes, and data flow documented and agreed before go-live.

