Security and trust
How Regulane protects the records you trust it with.
Policies, risks, evidence and incidents are some of the most sensitive records a business keeps. This page states what the code enforces, where your data is held, and what we do not claim.
14-day trial · No card required · Priced per workspace, never per seat
- Every record isolated, checked on every request
- Per workspace
- Life of a link to a stored file
- 5 min
- Hash-chained audit trail
- Append-only
- Full export of your workspace
- Any time
01Where your data lives
Every provider, named.
Data in a workspace is transferred outside India, which the DPDP Act 2023 permits except to countries the Government restricts by notification. Traffic is encrypted with TLS between your browser, our servers and each provider.
| What | Provider | Where |
|---|---|---|
| Application servers | VercelSingapore | Singapore |
| Workspace records | Prisma PostgresUnited States, AWS us-east-1 | United States, AWS us-east-1 |
| Uploaded files | Vercel Blob, privateVercel Blob storage | Vercel Blob storage |
| Sign-in accounts | Google FirebaseProvider’s regions, under its own terms | Provider’s regions, under its own terms |
| Transactional email | ResendProvider’s regions, under its own terms | Provider’s regions, under its own terms |
| AI requests, only when used | AnthropicProvider’s regions, under its own terms | Provider’s regions, under its own terms |
| Online payments | Cashfree PaymentsCard details never reach Regulane | Card details never reach Regulane |
The same list, with what each provider receives, is in the privacy notice.
02Access
Who can see what, and what it takes to sign in.
Roles
- Company adminEverything in the workspace, including members, plan and billing, integrations and the full export.
- ManagerRuns the modules, accepts evidence, and verifies corrective actions other people completed.
- EmployeeWorks on what is assigned to them, acknowledges policies and completes training.
- AuditorRead-only, and never takes a seat from the plan. Kept out of AI features.
Signing in and staying signed in
- Two-step verificationAuthenticator apps with recovery codes, held by Regulane and available to every account. A code is refused the second time it is used.
- Session cookieHttpOnly and SameSite=Lax, so page scripts cannot read it and other sites cannot send it with their requests.
- Workspace isolationEvery record is scoped to its workspace, and the scope is checked on the server on every request.
- Separation of dutiesDestroying a document needs a second approver, and a corrective action is verified by someone who did not do it. Enforced on the server, not drawn in the browser.
03Files and the audit trail
Evidence that cannot quietly change after the fact.
Files
- Stored privatelyA stored file has no public address. Reading one needs a signed link minted for that request.
- Links that expire after 5 minutesA link copied out of the app stops working shortly afterwards. Each read is logged.
- Versions and approvalsDocuments keep their versions, approvals and attestations; evidence records who uploaded it, when, and who accepted it.
- Uploads up to 4 MBLarger files are refused before anything is stored.
The audit trail
- Append-only and hash-chainedEach workspace’s entries are chained in the database itself, so an edit or a deletion after the fact would show when the chain is checked.
- No edits, no deletionsTriggers in the database refuse any change to an entry while the workspace exists, whoever asks. The trail is deleted with the workspace.
- Free text as a fingerprintNotes and descriptions are recorded as their length and a fingerprint, not the words, so personal data can still be corrected or erased from the record itself.
- Access logsWho signed in, from where, and what they opened.
04AI and integrations
What leaves your workspace, and only when you ask.
AI features
- Only when someone uses oneThe question and a summary of the relevant workspace records go to Anthropic’s Claude to produce the answer. Nothing is sent if AI features are not used.
- Nothing is sent on your behalfDrafted notices and answers are drafts. A person checks, files and approves them.
GitHub
- A read-only GitHub AppInstalled on the repositories your organisation’s owner chooses. Regulane stores no GitHub token.
- No source codeIt reads two-factor settings, owners, outside collaborators and branch rules. It does not read code, issues or pull requests, and cannot change anything.
Google Workspace
- Read-only, awaiting Google’s verificationReads the user directory for the 2-Step Verification, administrator and dormant-account checks. The access token is stored encrypted.
- Never sent to AIData from Google is not sold, not used for advertising or training, and not sent to Anthropic. Results are kept up to 90 days and deleted on disconnect.
05The platform
Headers, retention and the way out.
The browser protections every response carries, and what happens to your records when you leave.
On every response
- Strict transport securityHTTPS only, for two years, including every subdomain.
- Content Security PolicySigned-in pages allow only scripts carrying a per-request nonce. No page may be framed by another site.
- And the restnosniff, a strict referrer policy, and camera, microphone, location and payment APIs switched off.
Retention and leaving
- Export everythingA company admin can download every record in the workspace as one file at any time; registers export to PDF and CSV.
- Closing a workspaceIt is archived first: nobody can sign in, nothing is deleted, and it can be restored. On request, after at least 24 hours, it is permanently deleted, with every file and sign-in account.
- BackupsAny backup copy of the database is encrypted and kept for no more than 30 days, so deleted data leaves backups within 30 days.
What we do not claim, and how to report a problem
What we do not claim
- Regulane holds no SOC 2 or ISO 27001 certification of its own at this time. We will say so here until that changes, and add the report when it does.
- Regulane is not a certification body or an accredited auditor, and its materiality assessments are not legal advice.
- No method of transmission or storage is completely secure. What is above is what the code does, not a promise beyond it.
Found a security problem?
Email support@regulane.com with “Security” in the subject, and a person will reply.
Selling to your own customers? Every workspace can publish its own trust page, built from its records when it is opened and plain that it is not a certification.
Keep reading
- ISO 27001Annex A, clauses 4–10, the Statement of Applicability and audit preparation.
- DPDP ActThe Data Fiduciary obligations, the processing register, requests and breaches.
- Regulatory IntelligenceWhich regulatory changes name something you run, and why.
- PricingPer workspace, never per seat. Published, not quoted.
Regulation changes every week. Your compliance programme should know what changed, and what to do next.
14-day trial · No card required · Per workspace, never per seat
