Trust at Reuben AI
How we handle your data, access and privacy.
This page is maintained by Reuben Ventures Pty Ltd (t/a Reuben AI) to answer common security, privacy and compliance questions about the Reuben AI platform. It describes current practices and enabled controls; it is not an independent audit or certification and does not modify any contract, DPA or order form.
Access and authentication
User accounts are created per workspace. The platform supports:
- Email and password sign-in, with multi-factor authentication (MFA) available for users who choose to enable it.
- Google sign-in, which also powers optional Google Drive ingestion into the workspace.
- SSO/SAML for enterprise customers on request. Contact hello@goreuben.com.
Workspace administrators manage member invitations and permissions. Session and password controls follow current platform defaults.
Platform and hosting context
Reuben AI runs on managed cloud infrastructure. Customer data is isolated per workspace. Default data residency is Australia. European Union and United States regions are on the platform roadmap; residency requirements should be discussed with us before contracting so we can confirm what is available at the time of onboarding.
Transport to the platform uses HTTPS/TLS. Backups and encryption at rest are enabled at the infrastructure layer.
Data collection and use
The platform collects data that customers or their users submit (deal, portfolio, LP, document and workflow data), account metadata for authentication and billing, and standard application logs for operations and security.
Customer content is used to provide the service to that customer. Customer content is not used to train third-party foundation models. Any use of AI features against customer content is scoped to that customer's workspace.
Subprocessors and integrations
Reuben AI uses a small number of infrastructure and AI subprocessors to deliver the service. A current subprocessor list is available on request from hello@goreuben.com.
Optional customer-initiated integrations (for example Google Drive) only ingest data the customer authorises.
Retention and deletion
Customer data is retained for the duration of the customer's subscription. On termination, customer content is deleted from active systems within a commercially reasonable timeframe, subject to backup rotation and legal retention obligations. Specific retention terms can be captured in the order form or DPA.
Privacy requests
Data subjects and customers can raise privacy requests (access, correction, deletion, export) by writing to hello@goreuben.com. Where the customer is the data controller, we act on the controller's instructions.
Incident and security contact
Security incidents, suspected compromises and questions of a security nature should be sent to hello@goreuben.com. We acknowledge and triage reports promptly.
Vulnerability reporting
Responsible-disclosure reports are welcome at hello@goreuben.com. Please include a clear description, reproduction steps, and any impact assessment. We do not currently publish a numeric response-time SLA; we commit to promptly acknowledge and triage each report. Please do not test against production customer data.
Compliance posture
Reuben AI is not currently certified under SOC 2, ISO 27001 or equivalent frameworks. Where customers or regulators require specific evidence, we work through security questionnaires and can share our current control descriptions on request. Any compliance claim published in the future will be sourced to a named auditor and report reference.
Trust FAQs
Legal entity: Reuben Ventures Pty Ltd (t/a Reuben AI). Contact for all trust, privacy, security and enterprise procurement matters: hello@goreuben.com.