← Back to HomeSecurity & Compliance
Last Updated: July 21, 2025
At 1Grain.tech, data security and client trust come first. We build our own AI products — Laiers and awRAG.io — and bring that same engineering discipline to every client engagement. Our security practices are grounded in real-world production experience, not just theory.
Security Principles
GDPR Compliant
Full EU data protection compliance
Encryption in Transit
TLS 1.3 for all communications
Encryption at Rest
AES-256 for stored data
Privacy by Design
Security built in from the start
Data Encryption
Encryption in Transit
All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols (HTTPS). This ensures that communications cannot be intercepted.
- TLS 1.3 encryption
- 256-bit SSL certificates
- HTTPS-only policy
Encryption at Rest
Sensitive data is encrypted when stored using AES-256 encryption, protecting information even against unauthorized physical access.
Access Controls
We implement strict access controls to ensure data isolation and prevent unauthorized access:
- Row Level Security (RLS) policies on all database tables
- Multi-tenant data isolation
- Secure authentication with encrypted credential storage
- Role-based access control (RBAC)
- CSRF protection on all forms
GDPR Compliance
As a German company operating under EU jurisdiction, full GDPR compliance is foundational to our operations. Our commitments include:
- Transparent data processing practices
- Data minimization — collecting only what is necessary
- Purpose limitation — using data only for stated purposes
- Storage limitation — retaining data only as long as needed
- Lawful processing basis for all data operations
- Data breach notification within 72 hours as required
- Data Processing Agreements (DPAs) with all third-party processors
For detailed information about your data rights, please refer to our Privacy Policy.
Infrastructure Security
Our infrastructure leverages enterprise-grade providers with recognized certifications:
- SOC 2 Type II certified hosting infrastructure
- ISO 27001 certified data centers
- Automated backups and disaster recovery
- DDoS protection
- Network isolation and segmentation
- Real-time monitoring and alerting
Application Security
Beyond infrastructure, we implement application-level security controls:
- Input validation and sanitization on all user inputs
- Zod schema validation for API endpoints
- Rate limiting to prevent abuse
- Secure session management
- Bcrypt password hashing
- Regular dependency audits and updates
Client Data Handling
For client engagements, we follow these principles:
- Client data is processed only for the agreed-upon engagement scope
- Confidentiality agreements govern all client interactions
- Client data is returned or securely destroyed upon project completion
- No client data is used for model training or product improvement without explicit consent
- Separate environments isolate client work from internal systems
Incident Response
In the event of a security incident:
- Immediate incident containment and mitigation
- Affected parties notified without undue delay
- Supervisory authority notified within 72 hours where required by GDPR
- Forensic analysis and root cause investigation
- Implementation of corrective measures
Responsible Disclosure
We take security vulnerabilities seriously. If you discover a security issue in our systems or products, please report it responsibly:
Email: contact@1grain.tech with "Security Vulnerability" in the subject line
Include detailed information and steps to reproduce
We commit to acknowledging reports within 48 hours
Contact
For security-related questions or to request a Data Processing Agreement (DPA), contact us at contact@1grain.tech.