Privacy Policy
At RiskSensai, protecting your privacy is fundamental to our mission. We believe you should always know what data we collect, how we use it, and how we keep it safe.
Quick Navigation
1. Information We Collect
Information You Provide
Automatically Collected
Depending on the Services you use, a Customer may provide additional information to the Platform. This includes: answers to the Digital Trust Assessment, which are self-attested by the person completing it; an optional company domain that we use to run externally-observed public-internet checks (such as SPF, DMARC, DKIM, and TLS configuration and public breach-corpus lookups). These checks observe signals that are already available on the public internet; they are not intrusive scanning, vulnerability scanning, or penetration testing. We also collect evidence files you upload, which are stored in private, access-controlled storage; policies you generate or upload; and the records you manage in our privacy, vendor-risk, and incident-readiness tools, including data-subject-request (DSAR), records-of-processing (RoPA), and data-protection-impact-assessment (DPIA) records, vendor questionnaire responses, and incident records.
Controller and processor roles. For your own account and Organization information, RiskSensai (operated by TrustSensai, LLC, a Delaware limited liability company) acts as the controller. For personal data about your own employees, customers, or other data subjects that you, as the Customer, upload or manage inside these tools (for example, a DSAR or RoPA record about one of your data subjects), RiskSensai acts as a processor and handles that data only on your documented instructions; you remain responsible for having a lawful basis to provide it. A data-processing addendum covering this processor relationship is available on request.
Advisor marketplace. If you apply to join our marketplace as an Advisor (consultant), we collect application and verification information so we can vet independent consultants. This may include sensitive documents such as a government-issued identification, professional certifications, and certificates of insurance, along with engagement and referral records that connect Customers and Advisors.
Leads. If you submit a contact form or an assessment form, we collect the name, email, company, and stated need you provide so we can respond to you and follow up about the Services.
2. How We Use Your Information
When you are signed in, in-product assistant features can read and summarize information from your own account and readiness records to help you understand and manage them. These features only access data you already have access to. Any action that changes your data or sends something on your behalf requires your explicit confirmation; the assistant does not take such actions automatically.
Some general informational answers from our assistant are supported by references to RiskSensai's own content and are checked for consistency with those sources. RiskSensai is a software platform; it is not a law firm, a CPA firm, or an auditor, and it does not issue audit opinions or certifications. Assistant answers and platform outputs are informational only and are not legal, audit, or accounting advice.
3. Data Security
We implement industry-leading security measures to protect your personal information. Your data security is our top priority.
Encryption in Transit and at Rest
Data is encrypted in transit with TLS and encrypted at rest by our infrastructure providers. Uploaded evidence files are held in private storage that is not publicly accessible.
Access Controls
Role-based access controls and row-level security scope data to your account and organization. Sign-in supports OAuth providers, and account access is authenticated on every request.
Monitoring and Logging
We log application and access events and monitor for anomalies as part of our security operations.
Compliance Aligned
SOC 2-aligned controls, designed to support GDPR and CCPA obligations. RiskSensai is not itself certified as SOC 2 or ISO 27001; certification status, if and when achieved, will be published on our Security page.
4. Your Rights (GDPR/CCPA)
You have comprehensive rights regarding your personal data. We make it easy to exercise these rights.
To exercise any of these rights, contact us at privacy@trustsens.ai or use the privacy controls in your account settings. We respond within 30 days.
6. Third-Party Services
We work with trusted partners who are contractually obligated to protect your data:
Stripe
Payment processing (when billing is enabled)
Supabase
Database, storage, and authentication
Vercel
Hosting and infrastructure
Anthropic
AI assistant and analysis features
AI processing and OAuth sign-in
OpenAI
AI processing features
SendGrid
Transactional email delivery (when configured)
Optional OAuth sign-in
We use third-party artificial-intelligence providers to power our assistant and analysis features. Depending on the feature you use, the text or files you submit may be processed by one or more of these providers, including Anthropic, Google, and OpenAI. These providers process this information on our behalf to return a result; they are subject to their own terms and privacy commitments. We do not sell your information to these providers, and under the business API terms we use, these providers do not use the content you submit to train their general-purpose models.
If you choose to connect with an Advisor (an independent consultant such as a vCISO, privacy professional, or IT auditor) through the marketplace, we share relevant information about your engagement with that Advisor so they can review and assist with it. An Advisor is independent of RiskSensai and handles your information under their own professional and legal obligations. An Advisor may attest that a review was performed; an Advisor does not issue an audit opinion, a certification, or a guarantee on behalf of RiskSensai.
7. Data Retention
We retain your personal information only as long as necessary:
8. Contact Us
Privacy Team
For privacy-related inquiries, data requests, or concerns about how we handle your information.
Data Protection Contact
For GDPR-specific inquiries or to escalate privacy concerns. The controller of your account information is TrustSensai, LLC, a Delaware limited liability company, United States.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we'll also send you an email notification. We encourage you to review this policy regularly.
Questions About Your Privacy?
Our privacy team is here to help you understand how we protect your data
