Skip to main content
Your Privacy Matters

Privacy Policy

At RiskSensai, protecting your privacy is fundamental to our mission. We believe you should always know what data we collect, how we use it, and how we keep it safe.

Last Updated: July 20, 2026
SOC 2-aligned controls
GDPR Compliant
CCPA Compliant
256-bit Encryption

Quick Navigation

1. Information We Collect

Information You Provide

Account & Identity: Name, email, and a password or Google/Facebook sign-in identifier
Organization & Role: Organization membership, your role, and a record of your terms acceptance with consent IP
Assessment & Program Data: Digital Trust Assessment answers, uploaded evidence, policies, and readiness records you create
Payment Info: Billing details handled by Stripe; we do not store full card numbers
Communications: Messages, support requests, and feedback

Automatically Collected

Usage Data: Pages visited, features used, interactions
Device Information: IP address, browser, OS, device ID
Location Data: General location from IP address
Analytics: Performance metrics and error logs
Cookies: Session and preference data

Depending on the Services you use, a Customer may provide additional information to the Platform. This includes: answers to the Digital Trust Assessment, which are self-attested by the person completing it; an optional company domain that we use to run externally-observed public-internet checks (such as SPF, DMARC, DKIM, and TLS configuration and public breach-corpus lookups). These checks observe signals that are already available on the public internet; they are not intrusive scanning, vulnerability scanning, or penetration testing. We also collect evidence files you upload, which are stored in private, access-controlled storage; policies you generate or upload; and the records you manage in our privacy, vendor-risk, and incident-readiness tools, including data-subject-request (DSAR), records-of-processing (RoPA), and data-protection-impact-assessment (DPIA) records, vendor questionnaire responses, and incident records.

Controller and processor roles. For your own account and Organization information, RiskSensai (operated by TrustSensai, LLC, a Delaware limited liability company) acts as the controller. For personal data about your own employees, customers, or other data subjects that you, as the Customer, upload or manage inside these tools (for example, a DSAR or RoPA record about one of your data subjects), RiskSensai acts as a processor and handles that data only on your documented instructions; you remain responsible for having a lawful basis to provide it. A data-processing addendum covering this processor relationship is available on request.

Advisor marketplace. If you apply to join our marketplace as an Advisor (consultant), we collect application and verification information so we can vet independent consultants. This may include sensitive documents such as a government-issued identification, professional certifications, and certificates of insurance, along with engagement and referral records that connect Customers and Advisors.

Leads. If you submit a contact form or an assessment form, we collect the name, email, company, and stated need you provide so we can respond to you and follow up about the Services.

2. How We Use Your Information

Provide and improve the Services
Run your Digital Trust Assessment and readiness workspaces
Match Customers with vetted independent Advisors
Process payments securely (when billing is enabled)
Send service updates and alerts
Respond to support inquiries
Analyze usage to improve the product
Detect and prevent fraud and abuse
Comply with legal obligations

When you are signed in, in-product assistant features can read and summarize information from your own account and readiness records to help you understand and manage them. These features only access data you already have access to. Any action that changes your data or sends something on your behalf requires your explicit confirmation; the assistant does not take such actions automatically.

Some general informational answers from our assistant are supported by references to RiskSensai's own content and are checked for consistency with those sources. RiskSensai is a software platform; it is not a law firm, a CPA firm, or an auditor, and it does not issue audit opinions or certifications. Assistant answers and platform outputs are informational only and are not legal, audit, or accounting advice.

3. Data Security

We implement industry-leading security measures to protect your personal information. Your data security is our top priority.

Encryption in Transit and at Rest

Data is encrypted in transit with TLS and encrypted at rest by our infrastructure providers. Uploaded evidence files are held in private storage that is not publicly accessible.

Access Controls

Role-based access controls and row-level security scope data to your account and organization. Sign-in supports OAuth providers, and account access is authenticated on every request.

Monitoring and Logging

We log application and access events and monitor for anomalies as part of our security operations.

Compliance Aligned

SOC 2-aligned controls, designed to support GDPR and CCPA obligations. RiskSensai is not itself certified as SOC 2 or ISO 27001; certification status, if and when achieved, will be published on our Security page.

4. Your Rights (GDPR/CCPA)

You have comprehensive rights regarding your personal data. We make it easy to exercise these rights.

To exercise any of these rights, contact us at privacy@trustsens.ai or use the privacy controls in your account settings. We respond within 30 days.

5. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. You can manage your cookie preferences at any time.

Essential

Required for core functionality

Required

Analytics

Help us improve our services

Optional

Preferences

Remember your settings

Optional

We use a small number of first-party cookies to run the site, remember your preferences, and measure how people move through the Digital Trust Assessment and the Services, for example whether a suggestion was shown, clicked, and later led to starting an assessment, so we can improve our recommendations. This measurement uses first-party cookies and aggregate analytics and does not require you to be identified. Our current first-party cookies include auditsens_split and auditsens_exp_uid (used for product experiments) and NEXT_LOCALE (used to remember your language). We do not use third-party advertising trackers.

We use analytics to understand how features perform, including which versions of a message or page are most helpful (sometimes called A/B testing). This analytics information is used in aggregate to improve the Services. See our Cookie Policy below for the full, current list of cookies.

6. Third-Party Services

We work with trusted partners who are contractually obligated to protect your data:

Stripe

Payment processing (when billing is enabled)

Privacy

Supabase

Database, storage, and authentication

Privacy

Vercel

Hosting and infrastructure

Privacy

Anthropic

AI assistant and analysis features

Privacy

Google

AI processing and OAuth sign-in

Privacy

OpenAI

AI processing features

Privacy

SendGrid

Transactional email delivery (when configured)

Privacy

Facebook

Optional OAuth sign-in

Privacy

We use third-party artificial-intelligence providers to power our assistant and analysis features. Depending on the feature you use, the text or files you submit may be processed by one or more of these providers, including Anthropic, Google, and OpenAI. These providers process this information on our behalf to return a result; they are subject to their own terms and privacy commitments. We do not sell your information to these providers, and under the business API terms we use, these providers do not use the content you submit to train their general-purpose models.

If you choose to connect with an Advisor (an independent consultant such as a vCISO, privacy professional, or IT auditor) through the marketplace, we share relevant information about your engagement with that Advisor so they can review and assist with it. An Advisor is independent of RiskSensai and handles your information under their own professional and legal obligations. An Advisor may attest that a review was performed; an Advisor does not issue an audit opinion, a certification, or a guarantee on behalf of RiskSensai.

7. Data Retention

We retain your personal information only as long as necessary:

Active AccountAccount and product data retained while your account is active
30 DaysAccount and personal data deleted after a verified deletion request, typically within 30 days
7 YearsFinancial and tax records retained for up to 7 years as required by law
Listing + LegalMarketplace verification documents retained while the Advisor is listed and afterward as required for legal compliance
AnonymizedAggregated, de-identified analytics may be retained on an ongoing basis

8. Contact Us

Privacy Team

For privacy-related inquiries, data requests, or concerns about how we handle your information.

Response within 48 hours

Data Protection Contact

For GDPR-specific inquiries or to escalate privacy concerns. The controller of your account information is TrustSensai, LLC, a Delaware limited liability company, United States.

We have not appointed a Data Protection Officer or an EU/UK representative; if our processing activities change such that an appointment is required, we will identify them here. Privacy inquiries are handled via the contacts above.

Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we'll also send you an email notification. We encourage you to review this policy regularly.

Questions About Your Privacy?

Our privacy team is here to help you understand how we protect your data

Connecting to your conversation workspace…