Security and compliance

This page covers how Rastock AI protects your files, metadata and stock agency credentials, including encryption in transit and at rest, access controls, and how to export or delete your data.

Security-by-design and compliance-ready practices built to protect your data

Rastock AI is designed with security and privacy as foundational principles. Our platform follows recognized security and compliance frameworks to ensure responsible data handling, operational resilience, and regulatory readiness.

This page provides an overview of our current security posture and compliance approach.

Security & Compliance Position (Important Disclosure)

Rastock AI follows security-aligned practices and compliance frameworks. Formal third-party certifications are not yet issued but are part of our long-term compliance roadmap.

This disclosure is provided to ensure transparency and avoid overstating current certification status.

Rastock AI aligns its data processing practices with the principles of the General Data Protection Regulation, including:

Lawful, purpose-limited data processing

Privacy-by-design and data minimization

Support for data subject rights (access, deletion, portability)

Incident response and breach notification procedures

Rastock AI acts as a Data Processor when processing personal data on behalf of customers.

CCPA / CPRA (California, USA)

Rastock AI supports compliance with California privacy requirements through:

Consumer data access and deletion support

Opt-out mechanisms where applicable

Rastock AI does not sell or share personal data for advertising or profiling purposes.

Rastock AI aligns with generally accepted international privacy principles, including:

Data security and accountability

This alignment supports customers operating across multiple jurisdictions.

Data Protection & Encryption

Rastock AI applies encryption and data protection practices appropriate to the sensitivity of processed data, including:

Encrypted data transmission (TLS)

Encryption at rest for stored data

Secure key management practices

Access to systems and data is restricted based on operational necessity, including:

Role-based access control (RBAC)

Multi-factor authentication for internal systems

Rastock AI maintains monitoring and logging practices designed to:

Detect abnormal or unauthorized activity

Logs are retained in accordance with security and compliance requirements.

Business Continuity & Resilience

Rastock AI implements operational safeguards to support service continuity, including:

No system can guarantee uninterrupted availability, but reasonable measures are in place to reduce risk.

Data Processing & Sub-Processors

Rastock AI may engage trusted sub-processors to support hosting, analytics, and infrastructure operations.

Sub-processors are subject to confidentiality and data protection obligations

Data sharing is limited to what is necessary to deliver the service

Sub-processor usage follows a risk-based assessment approach

Details are available during enterprise onboarding or contractual review.

Audit & Enterprise Requests

Enterprise customers may request reasonable information regarding security and compliance practices during procurement or legal review.

Any audits or assessments are subject to:

Reasonable scope and notice

Security & Compliance Contact

For questions related to security, privacy, or compliance:

Legal Protection Statement (VERY IMPORTANT)

Nothing on this page shall be interpreted as a warranty, certification claim, or guarantee of compliance with any specific regulatory standard unless expressly agreed in writing.

This page is provided for informational purposes only.