Anyray ← Security & Compliance

Risk Assessment

Last updated: 30 June 2026

Anyray performs periodic risk assessments covering assessed risk levels, the maturity of its controls, and its standing against applicable regulations — including GDPR. This page states the practice and summarizes the standing; the detailed findings are shared on request.

Assessment cadence. Reviewed quarterly, and on any material change — a new provider, a new data flow, a schema migration, or a security incident triggers an out-of-cycle review rather than waiting for the quarter.

01Two perimeters

Anyray is self-hosted, so one assessment spans two perimeters with different owners. Almost everything runs in your environment; the only vendor-operated surface is the Portal account plane, and it carries content-free metadata only.

PerimeterWho operates itWho owns its risk assessment
Self-hosted deployment — gateway, optimizer, console, your PostgresYouYou. Anyray supplies the control inventory and audit evidence so you can run a deployment-specific assessment / DPIA.
Anyray Portal account plane — sign-in, tenant membership, billing (via Stripe), content-free usage rollups, pseudonymous seat hashesAnyray (vendor)Anyray. Assessed here as the vendor-operated surface; no prompt/response content ever reaches it.

02What the assessment covers

Each review rates, for both perimeters:

Detailed findings available on request. The full risk register and control-maturity ratings are part of Anyray's trust materials, shared under NDA on request — ask your Anyray contact or reach us through app.anyray.ai. The published pages carry the framework and current standing; the dated, point-in-time findings stay in the trust packet so they don't drift out of date here.

03Regulatory standing — GDPR

Anyray is GDPR-aligned, with controls mapped to SOC 2 and ISO 27001 criteria — assessed obligation by obligation below, not asserted in the abstract: System control = enforced by shipped behavior · Shared = system provides the mechanism, you operate it · Your program = controller obligation Anyray cannot discharge for you.

ArticleObligationHow Anyray stands
Art. 5(1)(f)Integrity & confidentialitySystem control — encryption at rest, admin-gated access, audit trails
Art. 5(1)(e)Storage limitationShared — retention knobs per store; you set the windows
Art. 6 / 13–14Lawful basis & noticesYour program — employment-context / legitimate-interest basis and employee notices
Art. 17Right to erasureSystem control — admin erasure endpoint (trace step manual)
Art. 20Data portabilitySystem control — admin export endpoint
Art. 25Data protection by design & defaultSystem control — content mode defaults to encrypted; stores are metadata-only
Art. 30Records of processingShared — the data inventory seeds your RoPA
Art. 32Security of processingSystem control — encryption, access control, DoS brakes, auditing
Art. 28 / 44+Processors & transfersYour program — agreements with upstream LLM providers, which receive prompts
Art. 35DPIAYour program — Anyray supplies inputs; you size it to your trace-retention window

For SOC 2, this assessment is the CC3 (risk assessment) artifact; access maps to CC6 and monitoring/audit to CC7, both covered under Compliance. Anyray holds its own SOC 2 Type I attestation; for your self-hosted deployment, the attestation program stays yours.

04Your own deployment assessment

You can re-run this for your environment each quarter using the evidence Anyray already exposes: confirm the stores, secrets, and services against the Asset Inventory; check your configuration against Security; route the per-domain audit logs to your SIEM; and record residual ratings for your deployment. The operational steps are documented at docs.anyray.ai/operate/compliance.

05Contact

Email: hi@anyray.ai