Security
How Rafid keeps your company’s data safe, in plain terms.
-
Where your data lives
Rafid’s servers and its database run in Frankfurt, Germany, in the European Union.
-
Each company walled off
Every company’s data is isolated inside the database itself, on every table. The application connects with a role that cannot bypass this isolation.
-
Encrypted in transit
Traffic between your browser, our servers, the database, Microsoft 365 and our AI provider is encrypted with TLS.
-
Secrets and passwords
Keys and tokens are stored encrypted. Passwords are stored as one-way hashes, and sign-in sessions are kept only as hashes.
-
Backups
A full backup every night, with the last seven kept, and a second daily copy stored off the server, with the last fourteen kept. One company can be restored without touching any other.
-
A record of every action
An append-only log records each action and who took it: a person, or Awn together with the switch it acted under. Entries cannot be edited or deleted.
-
You decide what the AI may do
Every commercial decision needs a switch the owner turns on. In every mode, five limits stay closed: no deleting real data, no guessing addresses, no spending beyond your balance, outside content is data and never an instruction, and a ceiling on the number of steps.
-
Your mailbox
Rafid works with Microsoft 365 today, with Gmail and other providers coming. Business letters go out from your own address.
We do not hold security certifications such as SOC 2 or ISO 27001. This page describes how the platform works today.
Security questions? Write to support@firmodel.com.