Privacy Policy
Last updated September 6, 2026
This policy explains what personal data Rayz Security ("Rayz Security," "we," "us") collects when you use our website and the Rayz Security service (the "Service"), why we collect it, where it is processed, and the choices you have. It applies to visitors of rayz-security.com and to people who sign in to the Service. Cookies are covered separately in our Cookie Policy.
1. Who is responsible
Rayz Security is the controller of the personal data described in this policy, except for the content your organization submits for review, which your organization controls and we process on its behalf (see section 4). For anything in this policy, write to support@rayz-security.com.
2. What we collect
Account and organization data. When you create an account we collect your name, work email address, a password (stored only as a salted hash), your role in the organization, and the organization's name, industry and compliance profile you enter during setup. If a colleague invites you, we receive your email address from them.
Content you submit. Change descriptions, technical context, design documents you paste or upload, Confluence pages and pull requests you import, the reviews, requirements and tasks generated from them, comments, decisions, and any internal policies you add under Guardrails.
Integration credentials. If you connect Jira, Confluence, GitHub or Slack, we store the tokens those services issue so the Service can act on your behalf. Tokens are encrypted at rest and are removed when you disconnect the integration.
Usage and activity. An activity log inside your organization (who created, approved or declined a review, and when), request logs with IP address, browser type and timestamps, and error reports, kept to run and secure the Service.
Billing data. Payments are handled by Paddle, our merchant of record. Paddle collects your billing name, address, tax details and payment method under its own privacy policy. We receive and store only your plan, subscription and customer identifiers, renewal dates and invoice status. We never see or store card numbers.
Contact and support. Anything you send us through the contact form or by email, including demo requests.
Website analytics. On the public website only, and only if you accept the cookie notice, Google Analytics collects page views, approximate location derived from a truncated IP address, and device and browser type. It is never loaded inside the signed-in Service.
3. Why we use it
- To provide the Service: authenticate you, run reviews, sync with your connected tools, notify your team, and bill your organization. This is necessary to perform our contract with you.
- To keep the Service secure: detect abuse, protect sign-up and sign-in against bots, investigate incidents, and keep an audit trail your organization can rely on. This is our legitimate interest.
- To support you and tell you about changes to the Service, your plan or these policies. Product announcements are sent only to account administrators and can be turned off by replying.
- To understand how the public website is used, with your consent.
- To comply with law, including tax and accounting obligations tied to paid plans.
We do not sell personal data, we do not use your content to train AI models, and we do not use it for advertising.
4. Content you submit and AI processing
Your organization owns the content it submits. We process it only to produce the review you asked for and to show it back to the people in your organization. To generate reviews, the relevant content is sent to a large language model hosted on Amazon Bedrock in our AWS region. Amazon Bedrock does not store prompts or completions after the response is returned and does not use them to train models. No other AI provider receives your content.
Nobody at Rayz Security reads your submitted content in the ordinary course of operating the Service. We access it only when you ask us to help with a specific review, or when it is strictly necessary to investigate a security incident or a fault, and we log that access.
5. Who we share it with
We use a small number of service providers, each bound by a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, file processing, AI inference (Bedrock) and transactional email (SES) | United States (N. Virginia) |
| Paddle.com Market Ltd | Merchant of record: checkout, invoicing, tax and payment processing | United Kingdom / European Union |
| Cloudflare | Turnstile bot protection on sign-up and sign-in forms | Global edge network |
| Google Analytics on the public website, only with your consent | United States |
When you connect an integration, data flows to and from that provider (Atlassian for Jira and Confluence, GitHub, Slack) under your own agreement with them. We send only what the integration needs: for example, a task title and description to create a Jira issue, or a review summary to a Slack channel you chose.
We may also disclose data when the law requires it, to protect the rights and safety of our users, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.
6. Where data is processed
The Service is hosted in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred there. We rely on our providers' data processing terms, which incorporate the European Commission's Standard Contractual Clauses and the UK Addendum, for those transfers. A data processing agreement for your organization is available on request for Team and Enterprise plans; Enterprise customers can also discuss hosting in a specific region.
7. How long we keep it
- Account, organization and content data: for as long as your organization's account is active. Deleting a review removes its content, generated output, tasks and comments immediately; the activity log keeps a one-line record that a deletion happened, without the content.
- When an organization closes its account, or asks us to, we delete its data within 30 days. Copies in encrypted backups expire within a further 30 days.
- Integration credentials: until you disconnect the integration or close the account.
- Request and security logs: up to 12 months.
- Billing records: as long as tax and accounting law requires, typically 7 years, held by Paddle and in our invoice records.
- Support correspondence: up to 24 months after the last message.
8. How we protect it
All traffic to the Service is encrypted in transit with TLS. Integration credentials are encrypted at rest with a key held outside the database. Access to production systems is limited to the people who operate the Service, protected by individual credentials, and every organization's data is isolated by tenant in the application layer. Sign-up and sign-in are protected against automated abuse, sessions use short-lived HttpOnly cookies, and passwords are never stored in readable form. If we ever discover a breach affecting your data, we will notify your organization's administrators without undue delay and, where the law requires, within 72 hours.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, have it deleted, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent where processing is based on consent. You can update your name and password in Settings, and administrators can remove members and delete reviews directly. For anything else, email support@rayz-security.com; we respond within 30 days and never charge for a reasonable request. If you are in the EEA or the UK and are not satisfied with our response, you can complain to your local data protection authority.
Deleting your account. To delete your account, or to close your organization and delete all of its data, email support@rayz-security.com from the address on the account. We verify the request, complete the deletion within 30 days, and confirm by email. Organization closure must come from an organization administrator.
If you use the Service through your employer's organization, your employer controls the content submitted and decides who has access to it. Requests about that content should go to your organization's administrator first; we will help them fulfil it.
10. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We will post any update here with a new "Last updated" date. If a change materially affects how we use your data, we will notify account administrators by email before it takes effect.
12. Contact
Questions, requests or concerns about privacy: support@rayz-security.com.