Trust Center

Everything your review team needs, in one place.

Security, privacy, availability, and assurance information for Risk Vault—what we can describe openly here, and how to request the current documentation package for the deployment option and release you are evaluating.

What this covers

Six areas, one review.

Each area below is described in the documentation package, scoped to the offering under consideration rather than to the product in general.

01

Architecture & isolation

Deployment models, tenant boundaries, service topology, and where customer data lives in each option.

02

Identity & authorization

Identity-provider support, MFA, roles, policies, claims, and the record-aware authorization model applied across the product.

03

Data protection

Encryption in transit and at rest, key-management choices, retention and deletion behavior, and export handling.

04

Availability & recovery

Backup approach, recovery objectives, monitoring, and the operational practices behind them for the selected environment.

05

Privacy & data handling

What the platform processes, how it is used, and the subprocessor position for the deployment you choose. See the Privacy Policy.

06

Assurance & compliance

Current assurance status, testing cadence, and the control evidence available to support your own framework mapping.

Documentation

Ask, and we send the current package.

1

Tell us what you are evaluating

The deployment option, the release, the regions involved, and the questionnaire or framework you need to satisfy.

2

We confirm scope and terms

Some materials are shared under confidentiality terms. We will say which, before you spend review time on them.

3

You receive dated materials

Every document is dated and tied to a release, so your file reflects the version you are actually assessing.

The package assembled for a security review typically includes:

  • Security overview for the release under review
  • Architecture and deployment description
  • Identity, access, and authorization model
  • Encryption and key-management summary
  • Logging, monitoring, and audit-record description
  • Backup, recovery, and continuity summary
  • Privacy, data-handling, and subprocessor summary
  • Current assurance and testing status

Completed vendor questionnaires are returned against the same materials, so the answers and the evidence stay consistent.

Request documentation
Working practices

How we operate between reviews.

Assurance is not a document you collect once. These are the practices the documentation describes in detail.

Least privilege by default

Administrative access is limited to named staff, reviewed periodically, and protected with multi-factor authentication.

Change with a record

Product and infrastructure changes move through review, and security-relevant actions leave audit records available to customers.

Vulnerability handling

Reports are triaged on receipt and remediated on a severity-driven timeline. See our responsible disclosure policy for how to reach us.

Incident response

A defined response process governs investigation and customer communication; notification commitments are set in your agreement.

Common questions

Before you ask.

Which certifications does Risk Vault hold?

Assurance and certification status depends on the deployment option and release, so it is shared with the current security package rather than stated here. That way the status you receive is the one that applies to what you are evaluating.

Where is our data stored?

It depends on the deployment model. Isolated options—including a customer-controlled AWS account—keep data in an environment you select. The architecture description covers data location for each option. See Security.

Do you use subprocessors?

The subprocessor position varies by deployment option and is documented in the privacy and data-handling summary provided with the package.

Can you complete our security questionnaire?

Yes. Send it with the deployment option and release you are evaluating, and we will answer it against the same materials in the documentation package.

How do we report a suspected vulnerability?

Email security@rkvault.com with enough detail to reproduce the issue. Our responsible disclosure policy sets out scope, safe harbor, and the response times you can expect.

What are the contract terms for data protection?

Data-protection terms are agreed during contracting. Ask for the current template alongside the security package, and review it with your counsel. The Terms of Use and Privacy Policy govern this website.

Start the security review early.

Send us the questionnaire and the deployment option you have in mind, and we will come back with the materials that answer it.