Credential boundaries
Workspace credentials are encrypted before storage. List APIs return masked metadata and fingerprints, not encrypted values or plaintext keys. Revocation actions are audited.
Trust Center
RaksHex is built to give teams control over AI access without turning customer prompts and provider keys into another source of risk.
Workspace credentials are encrypted before storage. List APIs return masked metadata and fingerprints, not encrypted values or plaintext keys. Revocation actions are audited.
Discovery ingests masked findings. Gateway policy evaluation can redact PII and records audit metadata without retaining raw prompts by default.
Workspace data is scoped by membership and can be exported or deleted through the product and support process. Retention and private-data-plane requirements are agreed for enterprise deployments.
RaksHex maps product controls to common frameworks and produces evidence. We do not claim a certification or independent audit until that assessment is complete and published.
For a DPA, security questionnaire, architecture review, or private deployment requirements, contact the RaksHex team before connecting production accounts.