RGX intercepts every payload before it hits an LLM — scrubbing PII, PHI, and financial identifiers in real-time. Every workspace is isolated at the data layer. Every redaction is logged to an immutable compliance event trail. Every Workspace Security Token is SHA-256 hashed. No plaintext credentials stored. No payload content persisted. This is what zero-leakage means in practice.
{{REDACTED_PHI_1}}, {{REDACTED_FIN_2}}) before any LLM call or database write. Token map is never stored — raw values discarded immediately after the scrub pass.[NAME_N] text. Either way, the name↔token mapping is held only in this process's memory, scoped to the calling session, purged automatically after 30 minutes of session idle time or immediately on session end — never written to disk, logs, or the database.LICENSE_KEY JWT — no outbound RGX network calls. Full deployment reference: /deploy.Each provisioned workspace operates in its own isolated data context. Usage events, billing aggregates, and security token data for one organization are never accessible to another — not through the platform, not through the dashboard, not even to us in normal operations. Complete data segregation is enforced at the database query level.
Your Master Organization Token is shown exactly once at provisioning. We immediately SHA-256 hash it before writing anything to the database — the plaintext token is never persisted. Authentication validates the incoming token's hash against the stored hash. Even a full database dump cannot reveal your token.
Message text and payload content transmitted through the protection layer is processed in memory only — it is never written to our database. We log metadata only: endpoint, timestamp, byte count, token count, and redaction event count. Your clients' regulated data does not live in our storage.
All sensitive configuration data — credentials, tokens, and internal keys used to operate the infrastructure — is encrypted with AES-256-GCM before being written to disk. All data is transmitted exclusively over TLS 1.3. Your data is unreadable without the encryption key even if someone accessed the server directly.
Data that passes through the protection layer is forwarded to our processing pipeline provider under a data processing agreement that prohibits use of submitted data for model training. If you enable passthrough mode to run your own model instead, RGX never forwards your data to any LLM at all — PHI/PII and person names are still scrubbed and tokenized in-memory exactly as above, and the clean text is returned directly to you. Nothing is stored either way.
All traffic is rate-limited to prevent abuse and brute-force attacks against your workspace. Invalid token attempts are tracked. Workspaces exhibiting anomalous usage patterns are flagged for review. Your token cannot be guessed — it is a 48-character hex string generated from a cryptographically secure random source.
Hosted on Render (SOC 2 Type II certified). Database on PostgreSQL with encrypted connections. All secrets managed via environment variables — never hardcoded. Infrastructure access restricted to authorized RGX Systems personnel only.
RGX runs on Render's SOC 2 Type II certified infrastructure — independently audited for Security, Confidentiality, and Availability. Audit period: October 2024 – September 2025.
Our infrastructure provider maintains a GDPR Data Processing Agreement (DPA). Partner operator data is handled in accordance with GDPR requirements. See our DPA for full details.
Every protected request passes through the Compliance Engine before any LLM call is made. Text is scanned for PII/PHI using industry-specific pattern sets, identifiers are replaced with numbered tokens ({{REDACTED_PHI_1}}, {{REDACTED_FIN_2}}), and the scrubbed text is what the model receives. Raw identifiers never leave your network.
Every request that triggers a redaction fires a non-blocking write to a permanent audit table — recording the timestamp, tenant_id, seat_id, redaction count, and pattern types matched. This log cannot be modified or deleted. It is the evidence trail a CISO or auditor can point to.
Email us at security@rgxsystems.com — we respond to every inquiry.
Get Started Free → Read our Data Processing Agreement →