Security
Ensuring the security of your data and operations is a top priority when using Agentic RAG.
Overview of Security Features
Agentic RAG incorporates multiple layers of security to protect your data and ensure compliance with industry standards. The following sections outline the key security features:
1. Data Encryption
At Rest
All data stored within Agentic RAG is encrypted using Advanced Encryption Standard (AES-256). This ensures that your data remains secure even if physical security is compromised.
In Transit
Data transmitted between your systems and Agentic RAG servers is encrypted using Transport Layer Security (TLS) protocols. This prevents interception and tampering during data transfer.
2. Access Control
Role-Based Access Control (RBAC): Agentic RAG supports role-based access control, enabling you to define roles and permissions for different users. This ensures that only authorized users can access sensitive information and functionalities.
Account Level Roles:
- Owner: Full administrative access, including managing users and settings.
- Member: Limited access, primarily for using the system without administrative privileges.
Knowledge Box Level Roles:
- Manager: Full control over the Knowledge Box, including managing content and users.
- Writer: Permission to add and modify all contents within the Knowledge Box.
- Reader: Read-only access to view all contents within the Knowledge Box.
When synchronizing contents from a third-party service (like Sitefinity, Sharepoint, ShareFile, Dropbox, etc.), the original access rights are not reproduced in the Knowledge Box. Consequently, if you invite a user in your Knowledge Box as a Reader (or higher level), they will be able to access all the contents, disregarding their actual access rights in the original system. The Knowledge Box must be considered as a technical service meant to be used by developers and administrators only. It is not an end-user tool.
3. Compliance and Certifications
Agentic RAG adheres to various industry standards and regulations to ensure the highest level of security and compliance, including:
- GDPR (General Data Protection Regulation)
- SOC 2 (System and Organization Controls)
- ISO 27001: An international standard for managing information security.
4. Regular Security Audits
Agentic RAG undergoes regular security audits and assessments by third-party security experts. These audits help identify and mitigate potential vulnerabilities, ensuring that our security measures are up-to-date and effective.