# Security

Every organisation on RALPH has a database of its own, in the UK or the EU. Inside it, the database itself refuses to show one organisation's rows to another, and every change to your records is recorded with who made it, people and Ralph alike.

## A database of its own

Every organisation runs in a database of its own. Your records never share a table with another organisation's. Alongside them, a shared database holds what RALPH needs to run the service around them: the organisations and where each one's database lives, sign-in identities and who belongs to which organisation, sessions and access grants (their secrets only as hashes), subscription and setup records, and the encrypted credentials for each organisation's database.

## In the UK or the EU

RALPH keeps each organisation's data in the UK or the EU. Today that means London: every organisation's database, RALPH's servers and the shared database run there. An organisation's region is set when it is set up, and can't be changed from within RALPH.

## Locked to your organisation

Inside your database, row-level security ties every row to your organisation, and the database enforces it, not just the application. RALPH's servers connect as a role that can't bypass it, and refuse to start if their connection could. A request that hasn't said which organisation it acts for sees nothing.

## Secrets encrypted at rest

The credentials RALPH uses to reach each organisation's database are kept encrypted, with XChaCha20-Poly1305. The keys that open them are held apart from the database, so a copy of the database alone holds only ciphertext, and they can be rotated.

## Sign-in and sessions

- **Sign in with Google.** RALPH asks Google for your basic profile, keeps only your name, your email address and Google's id for your account, stores no password, and keeps no Google token after you sign in.
- **Sessions stay on the server.** Your browser holds a random session id in a cookie that is `Secure`, `HttpOnly` and `SameSite=Strict`, bound to RALPH's own host. RALPH keeps only a hash of it.
- **Sessions end.** After 7 days unused, or 30 days at most, you sign in again. You can see your sessions and end any of them, and signing out clears what the browser holds.
- **Requests from other sites are refused.** A change made with your browser session is accepted only from RALPH's own pages.

## Connected apps and agents

Access keys for agents and scripts are stored only as hashes and carry scopes, and every key has an expiry date, a year ahead unless set otherwise. Apps you connect, such as Claude or ChatGPT, act only with access you grant: each access token lasts 15 minutes, and the grant behind it ends on its own after 90 days at most.

## Encrypted in transit

All traffic to RALPH is HTTPS. The API and the MCP server send `Strict-Transport-Security` on every response, so browsers never fall back to plain HTTP.

## Every change on record

Every change to your organisation's records is recorded in the same step as the change itself: who made it, with which credential, for whom, and when, Ralph included. The record can be added to but not edited, and your organisation's admins can read who made each change, for whom and when.

## Questions, answered

### Does RALPH share one database between customers?

No. Your organisation's records live in a database of its own. Alongside them, a shared database holds what RALPH needs to run the service around them: the organisations and where each one's database lives, sign-in identities and who belongs to which organisation, sessions and access grants (their secrets only as hashes), subscription and setup records, and the encrypted credentials for each organisation's database.

### Where is our data kept?

In London, UK. Every organisation's database, RALPH's servers and the shared database run there today. RALPH keeps your data in the UK or the EU.

### Does RALPH send our records to an AI model?

RALPH's own servers call no AI model. Ralph works through the AI assistant you connect, such as Claude or ChatGPT, under your own account, and sees only what your permissions allow.
