Security and governance

Enterprise security for regulated document work.

Encryption, access controls, audit logging, and governed AI processing support teams reviewing sensitive clinical, regulatory, CMC, quality, and technical documents.

Request security documentation
Security controls
Enterprise controlsDesigned for review

SECURITY CONTROLS

Security controls for
sensitive document workflows

Our security and privacy program is informed by control objectives from recognized frameworks. Framework references describe control design and alignment, not certification or attestation unless expressly stated in current documentation.

01

ISO 27001-aligned controls

Security policies, asset management, access control, and operational-security practices informed by ISO 27001 control themes.

02

SOC 2-aligned controls

Control design informed by the Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

03

Privacy principles

Privacy practices informed by data minimization, purpose limitation, access rights, security, and other principles reflected in GDPR.

04

Regulated workflow support

Review trails and human approval support drafting and pre-submission workflows. Raycaster is not, by itself, a validated GxP or 21 CFR Part 11 system of record.

Trusted data storage

Raycaster provides secure, flexible data storage designed for regulated life sciences teams working with sensitive clinical, regulatory, and quality documentation.

Tiered storage

Raycaster supports flexible storage options aligned with different data sensitivity levels, regulatory requirements, and internal compliance policies.

Regional data residency

Contracted data-residency options may be available for eligible enterprise deployments. Confirm current regions and requirements before submitting location-restricted data.

No Customer Content training

Customer Content is protected by workspace access controls. Raycaster does not use Customer Content to train or fine-tune generalized foundation models.

Security designed for regulated environments

Raycaster applies encryption, access control, audit logging, and review controls for regulated workflows where data integrity and traceability matter.

Access-control architecture

Access is verified, limited, and logged according to workspace roles and operational controls.

Approval-based access

Access to sensitive Customer Content is limited through approval controls that support regulated operational and support processes.

Security reviews and assessments

Internal security reviews and assessments help identify, mitigate, and manage potential risks across the platform.

Secure cloud infrastructure

Raycaster runs on cloud infrastructure configured to support secure, monitored document workflows.

Data ownership & operational control

You retain ownership of Customer Content. Access, retention, export, deletion, and residency options depend on your plan, configuration, and applicable agreement.

Data retention controls

Retention and deletion options support internal governance needs and vary by plan and contracted configuration.

Data governance

Gain visibility into how data is accessed, modified, and used across teams, supporting internal review, accountability, and traceability.

Encryption management

Customer Content is encrypted in transit and at rest. Contact us for current key-management options available to enterprise deployments.

User authentication

Authentication and access-management options support user control across organizations and teams.

CONTROL WITHOUT COMPROMISE

Maintain visibility, ownership, and
governance across all your data.

01

Retention policies

Available retention rules can be configured to support internal governance and contractual requirements.

02

Governance & audit visibility

Track how data is accessed, modified, and used across the platform to support internal review, accountability, and traceability.

03

Encryption controls

Protect sensitive information with encryption at rest and in transit and platform key-management practices.

04

Access & identity management

Enterprise options may include SSO, MFA, and role-based or team-based access controls, depending on plan and configuration.

FAQ

Raycaster maintains administrative, technical, and organizational safeguards designed to protect Customer Content, including encryption in transit and at rest, access controls, logging, and security monitoring.