Security architecture
built for trust
Deploy Recall Racoon inside your VPC, behind your firewall, with your compliance framework. We don't see your data. We don't train on your data. We can't.
Eight pillars of
memory security
Self-Hosted by Default
Run entirely on your infrastructure. No data leaves your network. Control Plane and Data Plane deploy as single binary or containers.
Namespace Separation
Hard isolation between workspaces. Separate encryption keys, separate vector indexes, separate audit logs. Cross-namespace access requires explicit permission.
Authentication & Authorization
API keys with scoped permissions (read/write/admin). SSO (SAML/OIDC) on Enterprise. RBAC with custom roles. Automatic key rotation and expiration.
Secret Handling
Auto-redaction of JWTs, AWS keys, SSH keys, Bearer tokens at ingest. Redaction patterns configurable per namespace. Original secrets never stored.
Encryption
AES-256 at rest for all Data Plane storage. TLS 1.3 for all transport. Optional customer-managed keys (BYOK) for Enterprise Private deployments.
Backups & Recovery
Point-in-time recovery from append-only WAL. Automated snapshots every 10k writes. Cross-region replication on Business/Enterprise. RPO < 5 min, RTO < 30 min.
Data Ownership
Your data, your rules. We never access your Stash, queries, or embeddings. No telemetry on content. Architecture enforces this—no policy required.
Private VPC / On-Premise
Deploy in your AWS/GCP/Azure VPC with PrivateLink/VPC Peering. Or on-premise on Kubernetes/VMs. Air-gapped with license-key validation (30-day grace).
Redaction at
ingest time
Secrets are the most common cause of memory leaks. Recall Racoon redacts them before they ever hit the Stash.
Detected & Redacted
- • JWT tokens (header.payload.signature)
- • AWS access keys (AKIA..., ASIA...)
- • AWS secret keys (40-char base64)
- • SSH private keys (-----BEGIN...PRIVATE KEY-----)
- • SSH public keys (ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256)
- • Bearer tokens (Authorization: Bearer ...)
- • API keys (sk-, pk_, ghp_, glpat_, etc.)
- • Database connection strings
- • Custom regex patterns (per namespace)
How It Works
- • Redaction runs at ingest, before any storage
- • Original content never written to disk
- • Redacted placeholder: [REDACTED:TYPE]
- • Alert sent to configured webhook (#security)
- • Audit log entry with hash of original
- • Configurable per namespace
- • Zero false-positive guarantee on patterns
Certifications &
attestations
We separate aspirational roadmap from shipped reality. Live items are available today. In Progress items have public timelines.
SOC 2 Type II
Audit-ready controls for security, availability, confidentiality. Target: Q3 2026. Controls implemented; formal audit pending.
ISO 27001
Information security management certification. Target: Q4 2026. ISMS implementation underway.
GDPR / CCPA
Data residency controls, right-to-erasure workflows, DPA on request. Implemented in product; customer configuration required.
HIPAA BAA
Business Associate Agreement available for healthcare deployments on Enterprise Private tier. Requires signed BAA and configuration review.
Security by
design, not policy
No Data Access by Design
The Control Plane and Data Plane run in your infrastructure. We operate zero infrastructure that touches your data on Private/Enterprise deployments. On Cloud Managed, we process but do not retain, aggregate, or train on your data. This is enforced by architecture—tenant isolation at the namespace level, encryption keys you control, and audit logs you own.
Supply Chain Security
- • Signed container images (cosign/sigstore)
- • SBOM published with every release
- • Dependency scanning (OSV, GitHub Advisory)
- • Reproducible builds
- • Minimal base images (distroless/scratch)
Incident Response
- • 24/7 security contact: security@recallracoon.com
- • Coordinated disclosure program
- • Patch deployment within 72 hours for critical
- • Customer notification within 24 hours of confirmed breach
- • Post-incident report published