Architecture & isolation
Deployment models, tenant boundaries, service topology, and where customer data lives in each option.
Security, privacy, availability, and assurance information for Risk Vault—what we can describe openly here, and how to request the current documentation package for the deployment option and release you are evaluating.
Each area below is described in the documentation package, scoped to the offering under consideration rather than to the product in general.
Deployment models, tenant boundaries, service topology, and where customer data lives in each option.
Identity-provider support, MFA, roles, policies, claims, and the record-aware authorization model applied across the product.
Encryption in transit and at rest, key-management choices, retention and deletion behavior, and export handling.
Backup approach, recovery objectives, monitoring, and the operational practices behind them for the selected environment.
What the platform processes, how it is used, and the subprocessor position for the deployment you choose. See the Privacy Policy.
Current assurance status, testing cadence, and the control evidence available to support your own framework mapping.
The deployment option, the release, the regions involved, and the questionnaire or framework you need to satisfy.
Some materials are shared under confidentiality terms. We will say which, before you spend review time on them.
Every document is dated and tied to a release, so your file reflects the version you are actually assessing.
The package assembled for a security review typically includes:
Completed vendor questionnaires are returned against the same materials, so the answers and the evidence stay consistent.
Request documentationAssurance is not a document you collect once. These are the practices the documentation describes in detail.
Administrative access is limited to named staff, reviewed periodically, and protected with multi-factor authentication.
Product and infrastructure changes move through review, and security-relevant actions leave audit records available to customers.
Reports are triaged on receipt and remediated on a severity-driven timeline. See our responsible disclosure policy for how to reach us.
A defined response process governs investigation and customer communication; notification commitments are set in your agreement.
Assurance and certification status depends on the deployment option and release, so it is shared with the current security package rather than stated here. That way the status you receive is the one that applies to what you are evaluating.
It depends on the deployment model. Isolated options—including a customer-controlled AWS account—keep data in an environment you select. The architecture description covers data location for each option. See Security.
The subprocessor position varies by deployment option and is documented in the privacy and data-handling summary provided with the package.
Yes. Send it with the deployment option and release you are evaluating, and we will answer it against the same materials in the documentation package.
Email security@rkvault.com with enough detail to reproduce the issue. Our responsible disclosure policy sets out scope, safe harbor, and the response times you can expect.
Data-protection terms are agreed during contracting. Ask for the current template alongside the security package, and review it with your counsel. The Terms of Use and Privacy Policy govern this website.
Send us the questionnaire and the deployment option you have in mind, and we will come back with the materials that answer it.