Skip to content
RiskTrace

Security & Trust

We publish what is true, not what is planned.

RiskTrace is built by a security consultancy for security teams. This page describes how the platform protects your data today and where our own compliance programme stands.

Data residency in Canada

Production runs in a Canadian region. A tenant region model records where each customer's data lives, and the choice is a property of the account rather than a line in a contract.

Isolation enforced where the data lives

Every table carries the tenant and row-level security enforces the boundary in the database. Privileged writes go through audited functions, not ad hoc queries.

Your keys, your storage

Enterprise customers bring their own encryption keys and can point evidence and document storage at their own cloud accounts. A private database per customer is available as an add-on.

Identity you control

Customer SSO, enforced MFA, invitation-based onboarding, auditor accounts that expire, and break-glass access that is logged and reviewed.

An audit trail you can hand over

Approvals, changes and exports are recorded with who, when and why. Reports are versioned so you can show exactly what the board was told.

AI off by default

No customer data reaches an AI provider until you turn processing on. The default endpoint is Canadian-region; you can bring your own keys; outputs are proposals until a person approves them.

Compliance programme

Where we stand, in plain terms.

RiskTrace and the company behind it are working toward SOC 2, ISO/IEC 27001 and ISO/IEC 42001. None of these is achieved yet, and we will not imply otherwise.

SOC 2 Type I and Type II

In progress

Controls implemented in the platform; audit readiness underway.

ISO/IEC 27001

In progress

ISMS being stood up alongside the SOC 2 work.

ISO/IEC 42001

In progress

AI management system covering the platform's own AI features.

WCAG 2.2 AA

Working conformance

Maintained conformance report; not a certification claim.

Penetration testing

Before launch

Independent testing of the platform before customer data is onboarded.

Reports and certificates will be published here as they are issued. Until then, ask us directly and we will tell you what exists.

Approvals and separation of duties

Approval separation defaults to reason mode: a person may approve their own change only with a recorded reason, and every approval is in the audit trail. Stricter modes are available per tenant.

Proposals, not direct writes

Imports, integrations and AI create proposals in a review queue. Nothing becomes an approved risk, control or policy without a person accepting it.

Accessibility as a product feature

Skip links, landmarks, keyboard and screen-reader paths and tagged PDF export are maintained against WCAG 2.2 AA, with a published working conformance report.

Incident response and disclosure

Security issues can be reported through the Frontier Cyber responsible disclosure process. Customers are notified of incidents affecting their data within the timelines in their agreement.

Subprocessors and data flows

A full subprocessor list with regions is published at launch. The design goal is a short list, all with Canadian or customer-selected regions.

Export and deletion

Tenant export jobs produce a complete copy of your data, and tenant deletion produces a certificate of destruction you can file.

Found something?

Report a vulnerability

We follow the Frontier Cyber responsible disclosure policy and respond to every report.

Responsible disclosure
Launching soon

Security questions before launch?

Leave a work email and mention security in the message; a practitioner, not a sales rep, replies.

One email when sign-up opens. No mailing list, no follow-ups.