Security at Reuben AI
A one-page overview of the controls enterprise buyers ask about most.
Maintained by Reuben Ventures Pty Ltd (t/a Reuben AI). Describes current practices and enabled controls. Not an independent audit or certification. For full context see Trust.
Authentication
Email and password with optional MFA. Google sign-in (also used for optional Google Drive ingestion). SSO/SAML available for enterprise customers on request.
Data isolation
Customer data is isolated per workspace. Access controls are enforced at the application and data layer.
Encryption
HTTPS/TLS in transit. Encryption at rest is enabled at the infrastructure layer.
Data residency
Default region is Australia. European Union and United States regions are on the platform roadmap. Confirm current options with us before contracting.
Subprocessors
A small number of infrastructure and AI subprocessors deliver the service. Current list available on request at hello@goreuben.com.
Use of AI
Customer content is used to serve that customer only. Customer content is not used to train third-party foundation models.
Logging and audit
Application actions are logged for operations and security. Investment decisions carry an in-product audit trail.
Compliance
Not currently certified under SOC 2 or ISO 27001. Security questionnaires supported on request.
Incident contact
Vulnerability reports
hello@goreuben.com. Acknowledged and triaged promptly. Please do not test against production customer data.
Enterprise procurement
For SSO/SAML, DPA, subprocessor list, security questionnaires, residency and any other enterprise procurement question, write to hello@goreuben.com.