RegWatch cloud
We run and update the platform. Your data is isolated from every other tenant in the database.

Where the data lives, who can see it, what the models may do with it, and how changes are recorded. Each answer describes how the product works today.
We run and update the platform. Your data is isolated from every other tenant in the database.
The full data plane runs in your own cloud account: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.
Every customer is a separate tenant, and the boundary is enforced in the database itself, not only in application code.
Postgres row-level security scopes each request to the organizations its session may reach.
Access follows roles, and RegWatch Legal chats and files stay private to their owner unless shared with the organization.
A file is served only after the request is authorized against the document’s record.
SAML and OIDC single sign-on connects RegWatch to your identity provider. Access is role-based, with 9 roles.
Organization Owner, Access Administrator and Audit Reviewer, for ownership, membership and read-only access reviews.
Viewer, Contributor or Manager, granted separately for RegWatch Compliance and for RegWatch Legal.
Subsidiaries or regions can be set up as an organization hierarchy, with access granted per organization.
Changes are written to a tamper-evident, append-only audit log. Entries are hash-chained, so a changed or removed entry breaks the chain and can be detected.
When, the actor, the entity, the action and the reason.
Audit Reviewer is a read-only role for security events and access reports.
Customer content is not used to train generalized AI models by default. To triage findings and answer questions, RegWatch sends the relevant text to its model providers.
Alerts carry the source URL, the dates and the verbatim excerpt, and assistant answers cite the records they rest on.
Agents read, score and draft. Obligations, owners and dismissals are decided by people, and a dismissal needs a written reason.
A Private VPC deployment calls the model providers with API keys you supply.
Run RegWatch in our cloud, or run the full data plane in your own cloud account with Private VPC: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.
We run and update the platform on Amazon Web Services, in the United States and the European Union. Your data is isolated from other tenants in the database.
The application, agents, database and documents run in your own cloud account.
Private VPC only reaches the model providers and the regulatory sources your watchlists read. Optional features such as email add their own destinations to your allow-list.
Hashed with Argon2id.
Validated on the server on every request, and revoked at sign-out.
Credentials for RegWatch Legal connectors are sealed with AES-256-GCM before they are stored.
Server-side fetches refuse private, link-local and cloud metadata addresses, guarding against server-side request forgery.
Production telemetry records operational metadata, not customer content.
Report a vulnerability to security@regwatch.io. The same contact is published in /.well-known/security.txt.
The affected URL or component, the steps to reproduce, and the impact you observed.
Test only against your own account, do not access other customers’ data or degrade the service, and give us time to fix the issue before you publish it.
Buy directly, through AWS Marketplace or through Azure Marketplace. Request the security review kit for your questionnaire, and the Data Processing Addendum that section 7 of the Terms of Service offers where you need one; the sub-processors that may process personal data for RegWatch are listed on their own page.
Customer content is not used to train generalized AI models by default, as section 7 of the Terms of Service sets out. The model providers receive only the text needed to triage or answer.
Yes. Private VPC runs the full data plane in your own cloud account, on AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider, with model-provider keys you supply. It only reaches out to the model providers and to the sources your watchlists read.
Yes: SAML and OIDC single sign-on. Roles are assigned in RegWatch, with governance roles and separate access to RegWatch Compliance and RegWatch Legal.
Email security@regwatch.io with the affected component, the steps to reproduce and the impact. Our security.txt lists the same contact.

Tell us which deployment you are reviewing, and send your questionnaire if you have one.