Skip to content
Security

Your data. Your keys. Your control.

RAUM AI is built security-first. Your customer data never passes through our AI accounts, personal info is masked before it ever reaches the AI, and every customer's data is fully separated.

Your own AI key

You connect your own OpenAI, Anthropic, or Google Gemini account directly. Your customer data flows from Zendesk to your AI provider — never through our AI accounts.

Your API keys
Encrypted at rest with AES-256-GCM via AWS KMS, with automatic key rotation.
Your data flow
Zendesk → RAUM (personal info masked) → your AI provider → Zendesk. No middleman in between.
No markup
You pay your AI provider directly, at cost. We never mark up what you pay for AI.

Personal data masking

Before any data reaches the AI, RAUM automatically finds and masks personal information in logs and AI requests. Names, emails, phone numbers, credit card numbers, and other sensitive details are replaced with placeholders — then restored in the final reply. (This is sometimes called "PII redaction" in security reviews.)

Example: What the AI sees
John Smith → [REDACTED_NAME]
[email protected] → [REDACTED_EMAIL]
4532-XXXX-XXXX-1234 → [REDACTED_CC]

Encryption at rest

All credentials, API keys, and sensitive configuration are encrypted at rest using AES-256-GCM via AWS KMS — the same standard banks and governments use. Encryption keys are rotated automatically on a regular schedule, and access is gated by strict IAM policies with least-privilege principles.

AES-256-GCM
Industry-standard authenticated encryption for all sensitive data at rest
Automatic key rotation
Encryption keys are rotated on a schedule with no service interruption

Strict data separation

Every customer's data is fully isolated at the database level. Your knowledge bases, decision trees, analytics, and API keys are completely separate from every other customer's. Nothing is shared, mixed, or accessible across accounts.

Data Residency

RAUM is hosted on AWS with infrastructure in the US. Data is processed in real time and not stored beyond what's needed for analytics and audit logging. Your AI provider's data policies apply to how they process your data.

Audit Logging

Every AI operation, admin action, and data access is logged with IP tracking and change history. Full audit trail for compliance and security review.

AI operations
Every reply generated, translation, grammar fix, and automatic resolution is logged
Admin actions
Settings changes, user modifications, and API key rotations
IP tracking
Source IP address recorded for every authenticated request

Have security questions?

Our team is happy to walk you through our security architecture, data handling practices, and compliance roadmap.