Skip to main content

Security

Security controls and their limits

Review the current controls and limits before sharing sensitive work. This page describes the design and open verification needs, alongside our Privacy Policy and Trust Center. RiskSensai is an advisory platform, not a CPA firm, and nothing it produces is an audit opinion or assurance.

Encryption in transit and at rest

Our hosting, database and storage providers support encryption in transit and at rest. Protection depends on the deployed service configuration; this page is not an independent assessment of that configuration.

Privacy Policy

Access control

Application access checks and database row-level security policies are designed to limit access by role and organization. Their presence does not establish complete protection across every workflow; authorization testing remains part of release review.

Transparency

Evidence hashes and provenance

The evidence locker records file hashes and provenance metadata for successful uploads. A hash can support a later byte comparison; it does not certify the source, accuracy or completeness of evidence. Event recording and verification coverage have limits, so we do not claim an immutable chain of custody.

Transparency

Logging and review

Selected workflows record activity and security events for review. Logging coverage and delivery are not guaranteed for every action; the current release must be checked for gaps and operational alerting.

Transparency

Compliance posture

The platform is built with SOC 2 principles in mind. We do not claim certifications we have not completed; formal certification status will be published here as it is achieved.

Privacy Policy

Data boundaries

Where data crosses into a provider or a scoped engagement context, we keep the boundary explicit. Details live in our Privacy Policy and Trust Center.

Payments stay with Stripe

Online checkout is not currently open. The billing integration is designed to use Stripe for card processing and to store subscription and payment references in RiskSensai. Confirm the available purchasing process with our team.

Privacy Policy

Organization access boundaries

Organization workspaces use membership checks, scoped records and row-level security policies. Authorized sharing and privileged service operations have additional boundaries that must be tested; this is not a blanket claim that every record has identical access rules.

Transparency

Advisor access is engagement-scoped

Where advisor access is available, review the engagement and sharing scope before granting it. A review request does not book an advisor. The planned Reviewed add-on is not yet available to purchase or schedule.

Transparency

AI providers

The AI copilot and drafting tools are powered by third-party AI providers (Anthropic, Google, and OpenAI); your inputs are processed by them to generate responses. See our Privacy Policy for details.

Responsible disclosure

Found something we should know about? Email security at trustsens.ai with the details, and include reproduction steps where you can. We respond within two business days.

Connecting to your conversation workspace…