Security, compliance and operations — in the open.
Sovereignty is only credible if it survives scrutiny. This is the posture a DACH due-diligence team expects: how RAGSuite is built, where your data lives, how we test and disclose, and how we keep it running.
Your data never leaves your perimeter.
RAGSuite runs entirely on systems you control — no RAGSuite cloud in between, and nothing shared with other customers (a self-contained, Docker-native stack). No shared tenancy, no external data store, no telemetry.
A self-contained stack
FastAPI services, PostgreSQL, Redis and a vector store (ChromaDB), orchestrated with Docker on infrastructure you control.
No outbound dependency
Runs with zero phone-home. The only external calls are to the model providers you explicitly configure — or none at all, with local Ollama.
Your encryption, your backups
Data at rest sits in your databases, under your key management and backup regime. You set residency, retention and recovery.
Keys you hold
Model-provider keys and the offline Enterprise licence key live with you. Nothing is brokered through us.
Built to be inspected.
Sovereignty is only credible if it survives scrutiny. Every claim below is backed by a documented policy — the depth a DACH due-diligence team expects.
Performance & SLOs
Defined latency and uptime targets, with SLA tiers behind Enterprise support.
Security & pentest
Documented security program with regular third-party penetration testing and a responsible-disclosure process.
Supply chain & CRA-readiness
Signed releases (cosign), a CycloneDX software bill of materials (SBOM), a coordinated vulnerability disclosure policy and a published security contact — engineered to the EU Cyber Resilience Act ahead of its 2027 obligations.
Versioning & upgrades
SemVer, a clear breaking-change policy, in-place CE→EE upgrades, and migration guarantees.
Backup & disaster recovery
Documented backup/restore and DR procedures for PostgreSQL, Redis and the vector store.
Full German UI
Complete German interface, not just translated strings — alongside German-language support (DE/EN).
Mobile app operations
Defined store-account, binary-signing and release ownership for the public mobile binary (Beta).
Accountable, and easy to reach.
A documented security program backs the platform — and a clear line to report anything.
Responsible disclosure
Found something? Email security@ragsuite.de — our security.txt (RFC 9116) lists the contact. We acknowledge reports and work them to resolution.
Built by NITSAN, in Germany and the EU
RAGSuite is an innovation by NITSAN, delivered in Germany through independent service partners, with support in German and English. Full legal details are in our Impressum.
No hidden sub-processors
Self-hosted means there is no RAGSuite sub-processor to assess. You add only the model providers you choose — documented for your records.
Documentation on request
Architecture notes, the DSGVO data-flow description, SLO definitions and the upgrade/versioning policy are available to evaluators under the Trust Center process.
Responsible disclosure: security@ragsuite.de · security.txt · Trust Center enquiries: trust@ragsuite.de
Built to outlast any one inbox
Every function at RAGSuite is reachable through a role-based address — sales@, support@, security@, privacy@ — never a single employee’s personal mailbox. Your support history, your security contact and your relationship don’t hinge on who’s still at their desk. A small thing that signals a larger one: a vendor built for the long, audited life of an enterprise deployment.
We practise what we preach
This website runs the way we tell customers to run RAGSuite: self-hosted fonts, no Google Analytics, Maps or third-party embeds, no trackers loaded before consent, and a browser Global Privacy Control signal honoured automatically. See exactly how this website handles your data, or read how to verify nothing phones home and whether you need a DPIA for RAG.
Ask the awkward questions.
Put your security review straight to our own documentation. Every answer cites the page it came from — which is the point.
Security & compliance, answered
What are the SLOs?
Latency and uptime targets are defined, with SLA tiers available under Enterprise support. Final figures are shared with evaluators under the Trust Center process.
How do upgrades and breaking changes work?
Semantic versioning with a clear breaking-change policy, in-place Community→Enterprise upgrades via an offline licence key, and documented migration guarantees.
How do you handle backup and disaster recovery?
Documented backup/restore and DR procedures cover PostgreSQL, Redis and the vector store. Because you host it, recovery runs on your own infrastructure and schedule.
Is the interface available in German?
Yes — a complete German interface, not just translated strings, alongside German-language support (DE/EN).
“Clever advertising today also means AI that’s accessible and sovereign. RAGSuite fits both.”
Verify our claims — then talk to us.
Signed releases, an SBOM, a citation on every answer, your own audit log. Bring your security questionnaire.