Security
Security controls and their limits
Review the current controls and limits before sharing sensitive work. This page describes the design and open verification needs, alongside our Privacy Policy and Trust Center. RiskSensai is an advisory platform, not a CPA firm, and nothing it produces is an audit opinion or assurance.
Encryption in transit and at rest
Our hosting, database and storage providers support encryption in transit and at rest. Protection depends on the deployed service configuration; this page is not an independent assessment of that configuration.
Privacy PolicyAccess control
Application access checks and database row-level security policies are designed to limit access by role and organization. Their presence does not establish complete protection across every workflow; authorization testing remains part of release review.
TransparencyEvidence hashes and provenance
The evidence locker records file hashes and provenance metadata for successful uploads. A hash can support a later byte comparison; it does not certify the source, accuracy or completeness of evidence. Event recording and verification coverage have limits, so we do not claim an immutable chain of custody.
TransparencyLogging and review
Selected workflows record activity and security events for review. Logging coverage and delivery are not guaranteed for every action; the current release must be checked for gaps and operational alerting.
TransparencyCompliance posture
The platform is built with SOC 2 principles in mind. We do not claim certifications we have not completed; formal certification status will be published here as it is achieved.
Privacy PolicyData boundaries
Where data crosses into a provider or a scoped engagement context, we keep the boundary explicit. Details live in our Privacy Policy and Trust Center.
Payments stay with Stripe
Online checkout is not currently open. The billing integration is designed to use Stripe for card processing and to store subscription and payment references in RiskSensai. Confirm the available purchasing process with our team.
Privacy PolicyOrganization access boundaries
Organization workspaces use membership checks, scoped records and row-level security policies. Authorized sharing and privileged service operations have additional boundaries that must be tested; this is not a blanket claim that every record has identical access rules.
TransparencyAdvisor access is engagement-scoped
Where advisor access is available, review the engagement and sharing scope before granting it. A review request does not book an advisor. The planned Reviewed add-on is not yet available to purchase or schedule.
TransparencyAI providers
The AI copilot and drafting tools are powered by third-party AI providers (Anthropic, Google, and OpenAI); your inputs are processed by them to generate responses. See our Privacy Policy for details.
Responsible disclosure
Found something we should know about? Email security at trustsens.ai with the details, and include reproduction steps where you can. We respond within two business days.
Related pages
Trust Center
Operating principles, platform transparency, and how the governed AI copilot is overseen.
Privacy Policy
What we collect, how we use it, your rights, and how we keep it safe.
Cookie Policy
The cookies we set, what each one does, and how to manage your preferences.
Accessibility Statement
The accessibility features built into the site and how to share feedback.
