> For the complete documentation index, see [llms.txt](https://help.rhythms.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.rhythms.ai/security-privacy-and-compliance/security-and-privacy.md).

# Security and Privacy

This article provides a high level overview. For more detailed information, head to [Trust Center](https://trust.rhythms.ai/)

Learn how Rhythms protects your data with enterprise-grade security, encryption, role-based access, and compliance.

## **How secure is Rhythms?**

Security is a top priority for Rhythms. The platform is built with enterprise-grade security measures at every level:​

* **Robust Infrastructure Protection**: Rhythms utilizes an advanced Web Application Firewall (WAF) with real-time threat detection, DDoS protection, and comprehensive edge security measures to guard against emerging threats. ​[rhythms.ai](https://www.rhythms.ai/platform/compliance)
* **Encryption Everywhere**: All data in Rhythms is encrypted end-to-end, with Bring Your Own Key (BYOK) support, allowing customers control over their encryption keys to secure sensitive information, credentials, and uploaded artifacts. ​[rhythms.ai](https://www.rhythms.ai/platform/compliance)
* **Access Control and Isolation**: Rhythms enforces strict role-based access control (RBAC) with granular permissions and time-bound access limitations. Each customer's data is processed in isolated environments, ensuring complete separation with no cross-tenant data exposure. ​[rhythms.ai](https://www.rhythms.ai/platform/compliance)
* **Certified and Tested**: Rhythms meets high security standards, including SOC 2 Type II certification, and conducts regular third-party penetration tests and security assessments to maintain its safeguards. ​

In practice, this means your data and operations within Rhythms are protected by enterprise-level security protocols and continuously monitored to keep your information safe.​

## **How does Rhythms protect my data privacy, and is it compliant with regulations?**

Rhythms is committed to data privacy and regulatory compliance. We adhere to global privacy laws, ensuring that your data rights are respected and protected. For example, we implement data minimization (only storing what is necessary) and give you control over data retention and deletion in line with these regulations.​

Importantly, your data in Rhythms is never used to train AI models or shared improperly. The platform follows a zero data retention policy for AI operations—any data processed by our AI features is immediately sanitized and not stored beyond its immediate use. All customer data remains within your Rhythms environment and is not mined or accessed for any purpose outside of providing the service to you. ​

Additionally, Rhythms ensures compliance through measures like detailed audit logs (so you can track who accessed what and when) and company-wide security training for our staff who handle data. We stay up-to-date with evolving privacy requirements and continually update our practices so that using Rhythms meets the highest privacy standards for your organization.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://help.rhythms.ai/security-privacy-and-compliance/security-and-privacy.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
