What your security review needs, in writing.

Where the data lives, who can see it, what the models may do with it, and how changes are recorded. Each answer describes how the product works today.

The answers reviewers ask for first.

RegWatch cloud

We run and update the platform. Your data is isolated from every other tenant in the database.

RegWatch cloudApplication and agentsPostgres with row-level security

Private VPC

The full data plane runs in your own cloud account: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.

Your cloud accountApplication and agentsDatabase and documents
Isolation
Tenant isolation enforced in the database with Postgres row-level security
Identity
SAML and OIDC single sign-on, and role-based access with 9 roles
Audit
Tamper-evident, append-only audit log
AI and your data
Customer content is not used to train generalized AI models by default
Deployment
Private VPC: the full data plane runs in your own cloud account

Data isolation

Every customer is a separate tenant, and the boundary is enforced in the database itself, not only in application code.

  • In the database

    Postgres row-level security scopes each request to the organizations its session may reach.

  • Inside your organization

    Access follows roles, and RegWatch Legal chats and files stay private to their owner unless shared with the organization.

  • Stored documents

    A file is served only after the request is authorized against the document’s record.

Access and identity

SAML and OIDC single sign-on connects RegWatch to your identity provider. Access is role-based, with 9 roles.

  • Governance roles

    Organization Owner, Access Administrator and Audit Reviewer, for ownership, membership and read-only access reviews.

  • Product roles

    Viewer, Contributor or Manager, granted separately for RegWatch Compliance and for RegWatch Legal.

  • Group structures

    Subsidiaries or regions can be set up as an organization hierarchy, with access granted per organization.

Audit trail

Changes are written to a tamper-evident, append-only audit log. Entries are hash-chained, so a changed or removed entry breaks the chain and can be detected.

  • What each entry records

    When, the actor, the entity, the action and the reason.

  • Who reviews it

    Audit Reviewer is a read-only role for security events and access reports.

AI and your data

Customer content is not used to train generalized AI models by default. To triage findings and answer questions, RegWatch sends the relevant text to its model providers.

  • Cited, not free-form

    Alerts carry the source URL, the dates and the verbatim excerpt, and assistant answers cite the records they rest on.

  • People decide

    Agents read, score and draft. Obligations, owners and dismissals are decided by people, and a dismissal needs a written reason.

  • Your keys in Private VPC

    A Private VPC deployment calls the model providers with API keys you supply.

Deployment

Run RegWatch in our cloud, or run the full data plane in your own cloud account with Private VPC: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.

  • RegWatch cloud

    We run and update the platform on Amazon Web Services, in the United States and the European Union. Your data is isolated from other tenants in the database.

  • Private VPC

    The application, agents, database and documents run in your own cloud account.

  • Network access you control

    Private VPC only reaches the model providers and the regulatory sources your watchlists read. Optional features such as email add their own destinations to your allow-list.

Infrastructure and application security

  • Passwords

    Hashed with Argon2id.

  • Sessions

    Validated on the server on every request, and revoked at sign-out.

  • Connector secrets

    Credentials for RegWatch Legal connectors are sealed with AES-256-GCM before they are stored.

  • Outbound requests

    Server-side fetches refuse private, link-local and cloud metadata addresses, guarding against server-side request forgery.

  • Telemetry

    Production telemetry records operational metadata, not customer content.

Responsible disclosure

Report a vulnerability to security@regwatch.io. The same contact is published in /.well-known/security.txt.

  • What to send

    The affected URL or component, the steps to reproduce, and the impact you observed.

  • What we ask

    Test only against your own account, do not access other customers’ data or degrade the service, and give us time to fix the issue before you publish it.

Procurement

Buy directly, through AWS Marketplace or through Azure Marketplace. Request the security review kit for your questionnaire, and the Data Processing Addendum that section 7 of the Terms of Service offers where you need one; the sub-processors that may process personal data for RegWatch are listed on their own page.

Questions

Do you use our data to train AI models?

Customer content is not used to train generalized AI models by default, as section 7 of the Terms of Service sets out. The model providers receive only the text needed to triage or answer.

Can RegWatch run inside our own cloud account?

Yes. Private VPC runs the full data plane in your own cloud account, on AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider, with model-provider keys you supply. It only reaches out to the model providers and to the sources your watchlists read.

Do you support single sign-on?

Yes: SAML and OIDC single sign-on. Roles are assigned in RegWatch, with governance roles and separate access to RegWatch Compliance and RegWatch Legal.

How do we report a vulnerability?

Email security@regwatch.io with the affected component, the steps to reproduce and the impact. Our security.txt lists the same contact.

Request the security review kit.

Tell us which deployment you are reviewing, and send your questionnaire if you have one.

Book a demo