# Security and trust

Canonical page: https://www.ask-myra.ai/security
Content reviewed: 23 September 2026.

[All pages](https://www.ask-myra.ai/llms.txt) · [Full website content](https://www.ask-myra.ai/llms-full.txt)

## Hero

**Eyebrow:** Security and trust

### Your research stays yours.

Your files and questions are never used to train a model. We have enterprise agreements for zero data retention with every model provider we use, including OpenAI, Anthropic and AWS. Access stays within the permissions you set.

At a glance

**Training on your work**

Never

**Kept by the models**

Nothing

**GDPR and DPDP**

We comply today

**SOC 2 Type II and ISO**

In progress

## The data path

**Eyebrow:** The data path

### Where your work goes, and where it stops.

Your files, projects and research stay within your organisation. Access is controlled by your team, and sharing is deliberate: a link you create or an export you request.

**Link:** See the workspace

**Visual description**

A boundary encloses the organisation’s files, projects, research and isolated code environment. Only user-directed sharing and exports cross it. A blocked route shows that the files do not become model-training material.

## The promises

**Eyebrow:** The promises

### Two columns, and no small print.

Most terms of service hide the answers in small print. Here they are in two columns: what we do with your files, your research and the people who can open them, and what we never do.

**Link:** How the research is done

**Visual description**

Two columns contrast permitted handling of client information with actions the service does not take. The comparison covers workspace separation, use for the client’s research, access permissions, model retention and training.

## Where we stand

**Eyebrow:** Where we stand

### We say in progress until the day it is not.

SOC 2 Type II and ISO are in progress. We are not certified yet, so we do not say we are. GDPR and DPDP are settled, and we comply with both today. The day a certificate is in our hands, this page will say so and carry the date.

**Link:** Send us your questionnaire

**Visual description**

A client security questionnaire becomes a written response in the client’s format, with the current audit status made visible.

## Common questions

**Eyebrow:** Questions

### Common questions

**Do you train on our data?**

No. Your files, your questions and the research that comes back are never used to train a model. The models that read your work keep none of it once the answer is done. That holds on every plan.

**Who can see our research?**

Inside your company, the people whose job allows it. Outside readers see only the report, dashboard or export you choose to share, and their questions stay within that research. When myRA brings in an industry specialist for expert review, that specialist sees only the study they are asked to help with.

**Do you support single sign-on?**

Not today. Each person signs in with their own account, and anyone can add a second step at login with an authenticator app. Tell us what your IT team needs and you get a straight answer in writing on what we can do and when.

## The paperwork

The paperwork

**Privacy policy**

What we collect, and why.

**Terms and conditions**

The contract behind the account.

**AI service terms**

The rules around the AI part of the service.

**Responsible AI**

What the models are allowed to do, and what they are not.

**Data retention policy**

How long anything is kept, and when it goes.
