Security

Security architecture
built for trust

Deploy Recall Racoon inside your VPC, behind your firewall, with your compliance framework. We don't see your data. We don't train on your data. We can't.

Core Security

Eight pillars of
memory security

Self-Hosted by Default

Run entirely on your infrastructure. No data leaves your network. Control Plane and Data Plane deploy as single binary or containers.

Namespace Separation

Hard isolation between workspaces. Separate encryption keys, separate vector indexes, separate audit logs. Cross-namespace access requires explicit permission.

Authentication & Authorization

API keys with scoped permissions (read/write/admin). SSO (SAML/OIDC) on Enterprise. RBAC with custom roles. Automatic key rotation and expiration.

Secret Handling

Auto-redaction of JWTs, AWS keys, SSH keys, Bearer tokens at ingest. Redaction patterns configurable per namespace. Original secrets never stored.

Encryption

AES-256 at rest for all Data Plane storage. TLS 1.3 for all transport. Optional customer-managed keys (BYOK) for Enterprise Private deployments.

Backups & Recovery

Point-in-time recovery from append-only WAL. Automated snapshots every 10k writes. Cross-region replication on Business/Enterprise. RPO < 5 min, RTO < 30 min.

Data Ownership

Your data, your rules. We never access your Stash, queries, or embeddings. No telemetry on content. Architecture enforces this—no policy required.

Private VPC / On-Premise

Deploy in your AWS/GCP/Azure VPC with PrivateLink/VPC Peering. Or on-premise on Kubernetes/VMs. Air-gapped with license-key validation (30-day grace).

Secret Handling

Redaction at
ingest time

Secrets are the most common cause of memory leaks. Recall Racoon redacts them before they ever hit the Stash.

Detected & Redacted

  • • JWT tokens (header.payload.signature)
  • • AWS access keys (AKIA..., ASIA...)
  • • AWS secret keys (40-char base64)
  • • SSH private keys (-----BEGIN...PRIVATE KEY-----)
  • • SSH public keys (ssh-rsa, ssh-ed25519, ecdsa-sha2-nistp256)
  • • Bearer tokens (Authorization: Bearer ...)
  • • API keys (sk-, pk_, ghp_, glpat_, etc.)
  • • Database connection strings
  • • Custom regex patterns (per namespace)

How It Works

  • • Redaction runs at ingest, before any storage
  • • Original content never written to disk
  • • Redacted placeholder: [REDACTED:TYPE]
  • • Alert sent to configured webhook (#security)
  • • Audit log entry with hash of original
  • • Configurable per namespace
  • • Zero false-positive guarantee on patterns
Compliance Status

Certifications &
attestations

We separate aspirational roadmap from shipped reality. Live items are available today. In Progress items have public timelines.

In Progress

SOC 2 Type II

Audit-ready controls for security, availability, confidentiality. Target: Q3 2026. Controls implemented; formal audit pending.

In Progress

ISO 27001

Information security management certification. Target: Q4 2026. ISMS implementation underway.

Available

GDPR / CCPA

Data residency controls, right-to-erasure workflows, DPA on request. Implemented in product; customer configuration required.

Available

HIPAA BAA

Business Associate Agreement available for healthcare deployments on Enterprise Private tier. Requires signed BAA and configuration review.

Architecture

Security by
design, not policy

No Data Access by Design

The Control Plane and Data Plane run in your infrastructure. We operate zero infrastructure that touches your data on Private/Enterprise deployments. On Cloud Managed, we process but do not retain, aggregate, or train on your data. This is enforced by architecture—tenant isolation at the namespace level, encryption keys you control, and audit logs you own.

Supply Chain Security

  • • Signed container images (cosign/sigstore)
  • • SBOM published with every release
  • • Dependency scanning (OSV, GitHub Advisory)
  • • Reproducible builds
  • • Minimal base images (distroless/scratch)

Incident Response

  • • 24/7 security contact: security@recallracoon.com
  • • Coordinated disclosure program
  • • Patch deployment within 72 hours for critical
  • • Customer notification within 24 hours of confirmed breach
  • • Post-incident report published
Deploy Securely

Choose your
deployment model