Built to the standard your auditors expect.
REGARA™ handles regulatory submissions, IP, and PHI. We've designed the platform — and the company — around the assumption that an inspector will eventually want to see how it works.
- 01No training on customer data.
Customer submissions, claims, and correspondence are isolated per tenant and never used to train shared foundation models. Customer-specific fine-tuning is opt-in and scoped to that customer's models only.
- 02Encryption everywhere.
TLS 1.3 in transit. AES-256 at rest. Customer-managed encryption keys (CMEK) available on enterprise plans — bring your own KMS root in AWS, Azure, or GCP.
- 03Single-tenant deployment.
For sensitive programs, REGARA™ deploys as a fully isolated single-tenant stack in the region of your choice. Available on enterprise plans.
- 04PHI-safe by default.
Infrastructure built for HIPAA compliance — program in progress, with a BAA planned for paid plans. Automatic PHI detection and redaction at ingest, with detection results available in the audit log.
A program, not a one-time audit.
ISO 27001 (ISMS) certification in progress. Compliance roadmap and Statement of Applicability available under NDA.
Request SoASOC 2 Type II examination in progress. Controls are monitored continuously ahead of our first report; roadmap available under NDA.
Request roadmapBusiness Associate Agreement planned for Pro and Enterprise plans. Architecture review with your privacy team on request.
Request BAAAnnual penetration test by a CREST-certified vendor. Executive summary shareable under NDA; remediation closes within published SLAs.
Request summary- ·Versioned model state.
Every model — base, fine-tuned, and retrieval index — is pinned to a version. Re-running a generation from six months ago produces an output identical to the original.
- ·Citation provenance.
Every cited document is hash-anchored. If a guidance document is updated, prior citations resolve to the version that was current at generation time.
- ·Hallucination controls.
Retrieval-grounded generation with claim-level verification. Outputs that can't be anchored to a source are flagged, not surfaced.
- ·Human-in-the-loop required.
REGARA™ does not submit to agencies. Every output passes through a reviewer with approval logged in the audit trail.
Documents you can share with your security team.
Certification roadmap and Statement of Applicability. Available under NDA.
High-level summary of REGARA™'s information security program.
Detailed architecture, data flows, and control mappings.
Send it. We answer within 48 hours.
CAIQ, SIG, custom — our security team handles the response. Walkthrough with your team on request.