Skip to main content
Trust & compliance

Security & privacy

Plant documentation is some of the most sensitive data you own. Raven keeps it inside your deployment boundary, processes it only to do the work you asked for, and never uses it to train AI models.

SOC 2 Type II — in progress
AES-256 / TLS 1.2+
RBAC + SSO
Single-tenant isolation
Zero retention · zero training
Deploy in your cloud
AI providers & subprocessors

What touches your data

Your deployment boundary

AWS · Azure · GCP

Your plant documents

P&IDs · SOPs · datasheets · permits

Raven models run inside

P&ID vision + search · no external transfer

Third-party AI providers

LLM · embedding · OCR — ephemeral API call

Zero retentionZero trainingNo human review

Provider

Role

How your data is handled

Raven (proprietary)

Role

Fine-tuned vision models for P&IDs and engineering drawings; fine-tuned search agents for retrieval across plant documentation.

How your data is handled

Runs inside your deployment boundary. No external data transfer.

LLM providers

Role

Language reasoning and response generation.

How your data is handled

Ephemeral API call. Zero retention, zero training, no human review.

Embedding providers

Role

Embedding generation for semantic search.

How your data is handled

Ephemeral API call. Zero retention, zero training, no human review.

OCR / vision providers

Role

Text and layout extraction from documents and drawings.

How your data is handled

Ephemeral API call. Zero retention, zero training, no human review.

Every third-party AI provider is contractually bound

  • No training on your data, or on the results generated from it

  • No retention of your data beyond the immediate processing window

  • No human review of your data by provider personnel

Configurable to your security posture

Not every deployment uses every provider. The exact data path is reviewed and agreed with your team during enterprise evaluation, and provider use can be restricted where operationally feasible.

Defense in depth

Security controls

Security Infrastructure

Raven's infrastructure is built with defense in depth. Protections include:

  • End-to-end encryption (TLS 1.2+ in transit, AES-256 at rest)

  • Least privilege access and identity management

  • Secure software development lifecycle with regular code review

  • Logical isolation of customer data per tenant

Operational Security

Raven continuously monitors the platform for threats. Controls include:

  • Incident response with defined severity levels and escalation

  • Intrusion prevention and automated alerting

  • Patch and vulnerability management with rapid remediation

Deployment & Access

Enterprises get fine-grained control over how Raven is deployed and who can use it:

  • Flexible deployment — Raven-managed, single-tenant, or your own cloud account

  • Role-based access control with SSO and full audit trails

  • Your data stays within your configured deployment boundary

  • SOC 2 Type II audit in progress; report available on completion

Data & ownership

Privacy

Retention & Deletion

By default, Raven retains your data only for the duration of the engagement, and purges it from primary stores and backups after termination on the agreed timeline. You can define custom retention windows to match your own governance requirements.

Ownership & Rights

You retain full ownership of your data. We publish clear policies on how data is collected and processed, and honour access, rectification, and erasure requests — sent to security@startraven.com — after verifying identity and authority.

Responsible AI

AI governance

Governance

Raven's AI features undergo legal, compliance, and technical review before launch, so AI use stays responsible and aligned with enterprise requirements.

Grounding & Traceability

Outputs are tied back to your source documents rather than presented as ungrounded model answers. Every response carries citations to the underlying documents and page references — so any answer can be checked against the record.

Human Review & Audit

Critical outputs run through review-and-correction loops before they count as validated, and user and system actions are logged for operational review. Improvement happens by re-ranking within your environment — never by training a model on your data.

Audited & reviewable

Compliance & review

SOC 2 Type II — audit in progress

Raven is undergoing a SOC 2 Type II audit under the AICPA framework, evaluating the design and operating effectiveness of our security, availability, and confidentiality controls over time. The report will be made available to customers on completion.

Review it with your team

Your IT and security team can evaluate Raven before go-live — an architecture walkthrough, answers to your security questionnaire, and a deployment-specific data-flow review. Request the Security Welcome Packet from security@startraven.com.

Always on

Reliability

Enterprise-Grade Infrastructure

Raven runs on enterprise cloud infrastructure — AWS, Azure, or GCP — with deployment in your own cloud account where required. The deployment region is agreed with you and can accommodate specific data-residency requirements.

High Availability & Monitoring

  • Multi-zone redundancy and backup systems

  • Proactive monitoring with alerting on operational failures

  • Availability targets defined in your deployment SLA

Deployment Reviews

Pilot and rollout deployments go through a joint review with your IT and security team — architecture, access routes, and data flow documented and agreed before go-live.

11Get Started

See Raven on your plant