Assessment cadence. Reviewed quarterly, and on any material change — a new provider, a new data flow, a schema migration, or a security incident triggers an out-of-cycle review rather than waiting for the quarter.
01Two perimeters
Anyray is self-hosted, so one assessment spans two perimeters with different owners. Almost everything runs in your environment; the only vendor-operated surface is the Portal account plane, and it carries content-free metadata only.
| Perimeter | Who operates it | Who owns its risk assessment |
|---|---|---|
| Self-hosted deployment — gateway, optimizer, console, your Postgres | You | You. Anyray supplies the control inventory and audit evidence so you can run a deployment-specific assessment / DPIA. |
| Anyray Portal account plane — sign-in, tenant membership, billing (via Stripe), content-free usage rollups, pseudonymous seat hashes | Anyray (vendor) | Anyray. Assessed here as the vendor-operated surface; no prompt/response content ever reaches it. |
02What the assessment covers
Each review rates, for both perimeters:
- Assessed risk levels — a risk register scoring each risk by likelihood × impact, before and after the shipped controls (the residual rating).
- Control maturity — every control domain (access, content privacy, credential handling, tenant isolation, DoS resistance, auditing, data-subject rights, retention, updates, transport security) rated on a five-level scale.
- Regulatory standing — mapped to GDPR and SOC 2, summarized below.
Detailed findings available on request. The full risk register and control-maturity ratings are part of Anyray's trust materials, shared under NDA on request — ask your Anyray contact or reach us through app.anyray.ai. The published pages carry the framework and current standing; the dated, point-in-time findings stay in the trust packet so they don't drift out of date here.
03Regulatory standing — GDPR
Anyray is GDPR-aligned, with controls mapped to SOC 2 and ISO 27001 criteria — assessed obligation by obligation below, not asserted in the abstract: System control = enforced by shipped behavior · Shared = system provides the mechanism, you operate it · Your program = controller obligation Anyray cannot discharge for you.
| Article | Obligation | How Anyray stands |
|---|---|---|
| Art. 5(1)(f) | Integrity & confidentiality | System control — encryption at rest, admin-gated access, audit trails |
| Art. 5(1)(e) | Storage limitation | Shared — retention knobs per store; you set the windows |
| Art. 6 / 13–14 | Lawful basis & notices | Your program — employment-context / legitimate-interest basis and employee notices |
| Art. 17 | Right to erasure | System control — admin erasure endpoint (trace step manual) |
| Art. 20 | Data portability | System control — admin export endpoint |
| Art. 25 | Data protection by design & default | System control — content mode defaults to encrypted; stores are metadata-only |
| Art. 30 | Records of processing | Shared — the data inventory seeds your RoPA |
| Art. 32 | Security of processing | System control — encryption, access control, DoS brakes, auditing |
| Art. 28 / 44+ | Processors & transfers | Your program — agreements with upstream LLM providers, which receive prompts |
| Art. 35 | DPIA | Your program — Anyray supplies inputs; you size it to your trace-retention window |
For SOC 2, this assessment is the CC3 (risk assessment) artifact; access maps to CC6 and monitoring/audit to CC7, both covered under Compliance. Anyray holds its own SOC 2 Type I attestation; for your self-hosted deployment, the attestation program stays yours.
04Your own deployment assessment
You can re-run this for your environment each quarter using the evidence Anyray already exposes: confirm the stores, secrets, and services against the Asset Inventory; check your configuration against Security; route the per-domain audit logs to your SIEM; and record residual ratings for your deployment. The operational steps are documented at docs.anyray.ai/operate/compliance.
05Contact
Email: hi@anyray.ai