Ralfi, Outlook assistant

Last modified 28 July 2026

Trust, Security & Privacy

When it comes to adopting new technology, we know that data privacy and security are at the forefront of everyone's mind, especially when it comes to AI. It is one of the most frequent and important topics we discuss with brokerages.

At Ralfi, we treat security as a core feature. Brokerages entrust us with sensitive client information, and we are committed to protecting it through rigorous security standards, transparent privacy practices and responsible AI deployment.

Our commitment is simple: your data remains your data. It is hosted in Australia, encrypted everywhere, never sold, and never used to train AI models.

1. Infrastructure & hosting

Ralfi runs entirely on Amazon Web Services (AWS) in the Sydney region (ap-southeast-2). Application logic, databases, file storage and AI processing all stay within Australian borders, meeting data sovereignty expectations for Australian brokerages.

  • Tier-1 cloud provider. All processing and storage occur in AWS data centres, which hold independent certifications including ISO 27001.
  • Network protection. Our services sit behind hardened, industry-standard network controls, with strict access rules and DDoS protection at the edge.
  • Isolated workloads. Compute runs in isolated, short-lived environments with a minimal attack surface. There are no long-lived, hand-managed servers.
  • Built to scale. The platform scales automatically with load, keeping availability and performance stable as your book grows.

2. Data protection

  • Encryption in transit. All data moving between your browser, your mailbox and our servers is encrypted with TLS 1.2+ (HTTPS).
  • Encryption at rest. Data is encrypted with 256-bit AES while stored in our databases and file storage.
  • Access control. We enforce role-based access control and the principle of least privilege across our systems. Access to production is restricted to authorised personnel and is logged.
  • Your inbox, on your terms. Ralfi connects to Microsoft 365 through Microsoft's own OAuth consent flow. We never see or store your password, and access can be revoked by your administrator at any time.

3. Authentication & payments

  • Identity. Sign-in is handled by WorkOS, an industry identity provider, with support for multi-factor authentication and enterprise SSO.
  • Payments. All payment processing is handled by Stripe, a PCI Service Provider Level 1. Ralfi never stores or processes your card details.

4. Responsible AI

Ralfi uses large language models to read renewal correspondence, draft follow-ups and fill documents. We are committed to using this technology safely:

  • Private by design. Models run on infrastructure we control, inside our Australian AWS environment. No third-party AI provider sees your data, retains it or trains on it.
  • Never trained on your data. Your emails, documents and client records are used to do your work, not to train models.
  • You stay in control. Nothing is sent to a client or insurer without a broker's approval, unless your brokerage explicitly turns on auto-send for a workflow.
  • Transparent and explainable. Everything Ralfi writes or fills in is shown to you before it is used, and every action is logged with a timestamp on the renewal record.

5. Your data stays yours

  • Export any time. Every renewal record can be exported as a single file with the full conversation, activity log, compliance steps and decisions, ready for an audit or a handover.
  • Delete any time. Ask us to permanently delete your data at any point. No lock-in.
  • Client links are controlled. Files shared with your clients travel as secure, tracked, expiring links under your own brokerage's branding.

6. Standards & practices

Our security controls follow ISO 27001-aligned practices: least-privilege access, encrypted data flows, audit logging, and separated environments. Every code change goes through automated testing, review and static security analysis before it reaches production.

7. Questions

We are happy to walk your team, your principal or your compliance adviser through any of this in detail. Reach us at hey@ralfi.io.