TRANSPARENCY
What leaves your network, and what doesn't
RaptorGRC runs entirely inside your own network as a container and can run fully air-gapped. Out of the box it makes no outbound calls, sends no telemetry, and never phones home to us. The only connections it ever opens are integrations you switch on and control, such as an optional cloud AI provider, a vulnerability scanner or your SSO, each off until you configure it. One thing does cross the gap, once, and only because you carry it across by hand, which is your offline activation code. This page tells you exactly what is in that code, what we do with it, and what never leaves your network at all. No small print.
Your offline activation code, and what is in it
Community Edition is activated offline. In RaptorGRC you click Generate activation request, which produces a short code (starting RGRC-REQ-1.). You copy that code and paste it into this licensing portal to get your signed licence back. The container itself opens no connection. You carry the code across, by copy and paste, once, at activation. The licence never expires, so there is no renewal.
That code carries what is needed to issue a licence and nothing more. A machine fingerprint, so the licence is bound to the installation you activated. The edition and product version. A one-time number that stops the same request being replayed. That is the whole of it.
Earlier versions of RaptorGRC also put a small usage summary in that code, being counts of records, a user count and the names of the built-in frameworks in use. We no longer collect it. If a code from an older deployment still contains one, it is discarded when the request is received and never written down. We have deleted what we previously held.
We stopped for a simple reason. The snapshot was taken at the moment you generated the request, which on a first install is a row of zeros, and because licences are perpetual there is no later moment that would ever send anything else. It was data we could not learn much from, and collecting it anyway sat badly with a product whose whole argument is that your compliance data stays in your building.
What is never collected
- No record contents. No risk, incident, policy, supplier or document data, ever.
- No personal data. No names, emails or usernames.
- No usage figures. No record counts, no user counts, no list of the frameworks you have adopted. We used to take a snapshot of those at activation and we no longer do.
- No names of anything you import. A framework you import is never named, since its name could itself be classified, so it never leaves your network.
- No continuous telemetry. Nothing is gathered or sent while you work, and nothing is sent after activation at all.
- No background network calls and no phone-home to us. Out of the box the container opens no connections at all; the only outbound connections it ever makes are integrations you switch on and point at endpoints you choose (an optional cloud AI provider, a scanner, your SSO).
You stay in control
Because activation is air-gapped copy-and-paste, you decide what crosses the gap. The code is plain, inspectable text, so you can decode it and read every field before you submit it. Once you are activated, nothing else is ever sent.
We have signed CISA's Secure by Design pledge
In August 2026, Biff Labs Ltd, the company behind RaptorGRC, signed CISA's Secure by Design pledge: a voluntary, public commitment to measurably reduce exploitable flaws in shipped software, covering MFA adoption, the elimination of default passwords, reducing whole classes of vulnerability, and transparency about the ones that remain.
What that looks like in practice here, today.
- Every account on this portal requires MFA, either a sign-in code by email or an authenticator app if you enrol one. RaptorGRC itself ships MFA with a per-role enforcement policy.
- No default credentials. A RaptorGRC deployment does not start until you set the admin credential, and this portal's staff accounts are held to the same MFA requirement as everyone else.
- Our release pipeline generates and signs a software bill of materials, a vulnerability scan report and build provenance for every build, and release downloads in the customer portal carry them.
- Security-relevant actions in RaptorGRC land in its audit log, so the evidence an intrusion investigation needs exists before anyone knows they need it. The pledge page sets out where that coverage has edges.
We track progress against all seven pledge goals, honestly, including the parts still in flight.