Procurement-ready answers,
without a sales call.
This page is built for security, procurement, and compliance reviewers. It answers the concrete questions you ask before approving a vendor: how RAXE turns agent activity into evidence you can verify, where data processes, what leaves your boundary, how our evidence maps to your governance frameworks, how to report a vulnerability, and the current SOC 2 posture.
How does RAXE turn activity into evidence?
Sealed by default, revealed on purpose, verifiable on demand. The record is the product – this is how it is built.
Sensitive fields – prompts, file paths, tool arguments – land sealed in RAXE Lineage Lens, the RAXE console. Analysts triage on structure, scores, and lineage, not on your data.
Unsealing a field takes a stated purpose and a click on Reveal. The reveal writes its own audit row – actor, field, outcome. Looking at evidence is itself evidence.
Every audit row is linked to the previous one by hash, so the ledger is tamper-evident. Run verification on demand and the chain answers with one word: Intact.
Fielding employee-privacy or works-council questions about watching engineers' agent sessions? Sealed-by-default already answers them: analysts triage on structure, scores, and lineage – not on what anyone typed – and unsealing a field requires a stated purpose and writes its own audit row.
An agent action arrives from one of four surfaces: gateway LLM traffic, in-app SDK events, AWS cloud activity, or kernel-observed file access from the host sensor.
The record names its witness: what the agent claimed at the gateway, what the application saw through the SDK, what the host sensor observed at the kernel – one timeline per agent session.
Explainable verdicts, not opaque scores: threat probability, per-family scores, out-of-distribution signal, and nearest known attack patterns, mapped to MITRE ATLAS and OWASP ASI.
Reviewer actions join the same record: triage outcome, each reveal with its stated purpose, and the audit rows those reveals created. An approval trail your auditors can verify, not reconstruct.
Process numbers come from our release gates, recorded on a live deployment – not marketing benchmarks. RAXE deploys observe-first: every would-block decision is logged with the evidence behind it. Today it lets you see it. Next, it lets you stop it.
Where does data process?
Data residency and where RAXE detection logic executes relative to your infrastructure.
RAXE is designed so detection runs inside your control boundary. The detection engine, classifiers, and scoring all execute on infrastructure you operate – self-hosted in your VPC or on your own hardware.
Telemetry and logs stay on your side unless you explicitly opt in to share anonymised signals with RAXE Intelligence. Prompt and response content is not transmitted to a RAXE-operated scanning cloud as part of normal operation.
- Default deployment: detection runs inside your environment.
- Data residency: follows your hosting region. We do not move traffic across regions.
What leaves your boundary?
Your prompts, detections, and evidence stay with you. Anonymised detection telemetry is the one configurable exception – off by default, shared only if you opt in.
- Prompts, responses, and session content
- Tool-call arguments and results
- Kernel-observed file-access records
- CloudTrail-derived cloud activity records – your CloudTrail is read in place by a collector running in your environment, never shipped to a vendor cloud
- Detection scores and verdicts
- The audit ledger and evidence exports
- Customer-specific configuration and policy
- Purpose: keeps detection signatures sharp across deployments.
- Your control: off by default for deployed products – share anonymised signals only if you explicitly opt in; the browser Detection Lab demo has its own one-click telemetry toggle (on by default, disclosed on the page).
The Browser Detection Lab demo on raxe.ai scans the prompt you paste as part of the detection walkthrough. Default on, toggle off in the demo.
What deployment models are supported?
Self-hosted in your environment. Validated paths today: Docker Compose, systemd, and the Python SDK. Kubernetes packaging is roadmap – stated plainly below.
Gateway, scoring, evidence store, and console all run inside your VPC. No RAXE-operated infrastructure in the traffic path. Signatures delivered via outbound HTTPS fetch.
Installed on hardware you operate, for organisations that keep AI workloads in their own racks. Same detection stack, same sealed evidence, same hash-chained ledger.
DaemonSet and sidecar packaging are on the roadmap, not shipping today. If K8s is your deployment target, ask us where it sits on the timeline before you plan around it.
The AWS CloudTrail reader runs self-hosted alongside the rest of RAXE and needs read-only access to your CloudTrail. Early access – design partner programme; findings are correlated to agent sessions, not exact attribution; demo views use clearly-labelled sample data. How the AWS lane works →
How does RAXE evidence map to your frameworks?
Governance mappings: how the RAXE record supports your control obligations. Every entry links to the primary source.
These are governance mappings, not certification claims. They describe how RAXE evidence – the runtime record, the audited reveal trail, the hash-chained ledger – supports obligations you hold under each framework. Detection itself is mapped to MITRE ATLAS and OWASP ASI, the AI-specific threat frameworks, not to compliance frameworks.
Vulnerability disclosure
How to report a security issue responsibly, what is in scope, and our safe-harbour commitment.
Security research evidence
Public research output as proof of security maturity.
SOC 2 posture
The current state of our SOC 2 programme and what we can share today.
SOC 2 programme status: in progress. RAXE has aligned internal controls to the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) and is working through formal audit readiness. We do not claim a completed SOC 2 Type II audit.
For enterprise evaluations we can share the following under NDA:
- Control matrix mapped to SOC 2 TSC
- Current audit timeline and auditor relationship (when established)
- Security questionnaire responses (SIG Lite, CAIQ v4)
- Data processing agreement and sub-processor list
Ask the team for the current status: security@raxe.ai or book a walkthrough →.
Still have questions?
Book a 30-minute call with a RAXE engineer. No sales funnel.