← Back to Home

Security & Compliance

Last Updated: July 21, 2025

At 1Grain.tech, data security and client trust come first. We build our own AI products — Laiers and awRAG.io — and bring that same engineering discipline to every client engagement. Our security practices are grounded in real-world production experience, not just theory.

Security Principles

GDPR Compliant

Full EU data protection compliance

Encryption in Transit

TLS 1.3 for all communications

Encryption at Rest

AES-256 for stored data

Privacy by Design

Security built in from the start

Data Encryption

Encryption in Transit

All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols (HTTPS). This ensures that communications cannot be intercepted.

  • TLS 1.3 encryption
  • 256-bit SSL certificates
  • HTTPS-only policy

Encryption at Rest

Sensitive data is encrypted when stored using AES-256 encryption, protecting information even against unauthorized physical access.

Access Controls

We implement strict access controls to ensure data isolation and prevent unauthorized access:

  • Row Level Security (RLS) policies on all database tables
  • Multi-tenant data isolation
  • Secure authentication with encrypted credential storage
  • Role-based access control (RBAC)
  • CSRF protection on all forms

GDPR Compliance

As a German company operating under EU jurisdiction, full GDPR compliance is foundational to our operations. Our commitments include:

  • Transparent data processing practices
  • Data minimization — collecting only what is necessary
  • Purpose limitation — using data only for stated purposes
  • Storage limitation — retaining data only as long as needed
  • Lawful processing basis for all data operations
  • Data breach notification within 72 hours as required
  • Data Processing Agreements (DPAs) with all third-party processors

For detailed information about your data rights, please refer to our Privacy Policy.

Infrastructure Security

Our infrastructure leverages enterprise-grade providers with recognized certifications:

  • SOC 2 Type II certified hosting infrastructure
  • ISO 27001 certified data centers
  • Automated backups and disaster recovery
  • DDoS protection
  • Network isolation and segmentation
  • Real-time monitoring and alerting

Application Security

Beyond infrastructure, we implement application-level security controls:

  • Input validation and sanitization on all user inputs
  • Zod schema validation for API endpoints
  • Rate limiting to prevent abuse
  • Secure session management
  • Bcrypt password hashing
  • Regular dependency audits and updates

Client Data Handling

For client engagements, we follow these principles:

  • Client data is processed only for the agreed-upon engagement scope
  • Confidentiality agreements govern all client interactions
  • Client data is returned or securely destroyed upon project completion
  • No client data is used for model training or product improvement without explicit consent
  • Separate environments isolate client work from internal systems

Incident Response

In the event of a security incident:

  • Immediate incident containment and mitigation
  • Affected parties notified without undue delay
  • Supervisory authority notified within 72 hours where required by GDPR
  • Forensic analysis and root cause investigation
  • Implementation of corrective measures

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue in our systems or products, please report it responsibly:

Email: contact@1grain.tech with "Security Vulnerability" in the subject line
Include detailed information and steps to reproduce
We commit to acknowledging reports within 48 hours

Contact

For security-related questions or to request a Data Processing Agreement (DPA), contact us at contact@1grain.tech.